feat(pgsql): add WhereGroup and a podman/docker hardening test

- PgSQLSelectQuery implements common.WhereGrouper so x-custom-sql-or
  is grouped with the client's own conditions on the pgx adapter too.
- Add a container test (opt-in via RESOLVESPEC_TEST_CONTAINERS=1) that
  starts PostgreSQL with podman or docker and checks the hardening
  against a real database: parenthesis escape, pg_sleep, catalog
  subquery, stacked statements, x-custom-sql-or grouping and the
  legacy behaviour when hardening is switched off.
This commit is contained in:
Hein
2026-10-01 14:41:46 +02:00
parent ca89cb8a73
commit f54b707040
5 changed files with 282 additions and 1 deletions
@@ -29,3 +29,22 @@ func TestBunWhereGroupConfinesOr(t *testing.T) {
t.Fatalf("unexpected SQL:\n got: %s\nwant to contain: %s", got, want)
}
}
func TestPgSQLWhereGroupConfinesOr(t *testing.T) {
var q common.SelectQuery = &PgSQLSelectQuery{driverName: "postgres", tableName: "items", columns: []string{"*"}, args: []interface{}{}}
q = q.Where("a = ?", 1)
q = q.(common.WhereGrouper).WhereGroup(func(g common.SelectQuery) common.SelectQuery {
return g.Where("b = ?", 2).WhereOr("(c = 3)")
})
q = q.Where("tenant = ?", 5)
pq := q.(*PgSQLSelectQuery)
got := pq.buildSQL()
want := `WHERE (a = $1 AND ((b = $2) OR (c = 3)) AND tenant = $3)`
if !strings.Contains(got, want) {
t.Fatalf("unexpected SQL:\n got: %s\nwant to contain: %s", got, want)
}
if len(pq.args) != 3 || pq.args[0] != 1 || pq.args[1] != 2 || pq.args[2] != 5 {
t.Fatalf("args out of order: %v", pq.args)
}
}