feat(pgsql): add WhereGroup and a podman/docker hardening test

- PgSQLSelectQuery implements common.WhereGrouper so x-custom-sql-or
  is grouped with the client's own conditions on the pgx adapter too.
- Add a container test (opt-in via RESOLVESPEC_TEST_CONTAINERS=1) that
  starts PostgreSQL with podman or docker and checks the hardening
  against a real database: parenthesis escape, pg_sleep, catalog
  subquery, stacked statements, x-custom-sql-or grouping and the
  legacy behaviour when hardening is switched off.
This commit is contained in:
Hein
2026-10-01 14:41:46 +02:00
parent ca89cb8a73
commit f54b707040
5 changed files with 282 additions and 1 deletions
+6 -1
View File
@@ -1,6 +1,11 @@
# pkg/security lookup sub package plan
Status: plan only, no code changed. Related: `audit/mcp_plan.md` (work item 1, API key login).
Status: implemented (steps 0-7). What shipped and every API change is recorded in `pkg/security/breaking_changes.md`;
usage is documented in `pkg/security/README.md` ("Database access (lookup)"). This file is kept as the design record.
Deviations from the plan below: only `totp` and `providers` were split out of `pkg/security` (no `oauth` package, the
OAuth server and passkey provider stay in `security`), the `Database*` constructors stay in `security`, and
`ddl/postgres.sql` is tables only and cannot be combined with the procedure schema.
Related: `audit/mcp_plan.md` (work item 1, API key login).
## Problem