mirror of
https://github.com/bitechdev/ResolveSpec.git
synced 2026-10-02 11:31:57 +00:00
feat(pgsql): add WhereGroup and a podman/docker hardening test
- PgSQLSelectQuery implements common.WhereGrouper so x-custom-sql-or is grouped with the client's own conditions on the pgx adapter too. - Add a container test (opt-in via RESOLVESPEC_TEST_CONTAINERS=1) that starts PostgreSQL with podman or docker and checks the hardening against a real database: parenthesis escape, pg_sleep, catalog subquery, stacked statements, x-custom-sql-or grouping and the legacy behaviour when hardening is switched off.
This commit is contained in:
@@ -9,6 +9,7 @@
|
||||
| **Docs** | `README.md`, `SECURITY_FEATURES.md`, `QUICK_REFERENCE.md`, `OAUTH2.md`, `OAUTH2_REFRESH_*.md`, `PASSKEY_QUICK_REFERENCE.md`, `KEYSTORE.md` |
|
||||
| **Tests** | 6 359 lines across 13 `_test.go` files |
|
||||
| **Audit date** | 2026-09-29 |
|
||||
| **Note** | Point-in-time snapshot. File names and line numbers refer to the code as audited. Since then all SQL moved out of `pkg/security` into `pkg/security/lookup`: `providers_direct.go`, `sql_names.go`, `table_names.go`, `query_mode.go` and `password.go` are gone, `SQLNames` / `TableNames` / `QueryMode` became `lookup.Config`, and the SQL files moved to `pkg/security/lookup/`. See `pkg/security/breaking_changes.md` for the mapping. |
|
||||
| **Axes** | thread locking/waiting, slowness, security, panic handling & logging |
|
||||
| **Threat model** | hostile internet client; request bodies, headers, query params, schema/table/column names and filter expressions all attacker-controlled |
|
||||
| **Depth** | deep |
|
||||
|
||||
@@ -1,6 +1,11 @@
|
||||
# pkg/security lookup sub package plan
|
||||
|
||||
Status: plan only, no code changed. Related: `audit/mcp_plan.md` (work item 1, API key login).
|
||||
Status: implemented (steps 0-7). What shipped and every API change is recorded in `pkg/security/breaking_changes.md`;
|
||||
usage is documented in `pkg/security/README.md` ("Database access (lookup)"). This file is kept as the design record.
|
||||
Deviations from the plan below: only `totp` and `providers` were split out of `pkg/security` (no `oauth` package, the
|
||||
OAuth server and passkey provider stay in `security`), the `Database*` constructors stay in `security`, and
|
||||
`ddl/postgres.sql` is tables only and cannot be combined with the procedure schema.
|
||||
Related: `audit/mcp_plan.md` (work item 1, API key login).
|
||||
|
||||
## Problem
|
||||
|
||||
|
||||
Reference in New Issue
Block a user