Commit 1fbaaf1
fix(editor): close SQL guard bypasses in the query editor (#63)
A CHAT_EDITOR (non-admin) user could delete or overwrite every row in
any table by wrapping the write in a CTE. `WITH x AS (DELETE FROM t
RETURNING *) SELECT * FROM x` parses as a Select, so classification
returned read-only and returned before the admin check ever ran.
PostgreSQL executes data-modifying CTEs for real. Verified end to end: 3
rows -> 0, success:true, no confirmation prompt, logged as an ordinary
EDITOR_QUERY_EXECUTED / SUCCESS.
- classifyStatement now walks the parse tree for data-modifying CTEs and
SELECT ... INTO (detectSelectWrite), with a text backstop
(detectHiddenWrite) so an unparseable variant fails closed instead of
reaching isReadOnlyQuery, which reports anything starting with WITH as
safe.
- READ_ONLY_ONLY contexts now open read-only JDBC sessions, so the
database refuses the write even when classification is wrong.
Classification is a parser heuristic; this is what keeps the next parser
gap from being data loss. HikariCP resets the flag on return to the
pool, verified, so it cannot leak into an admin's later write.
- Row caps are enforced with setMaxRows instead of a `\blimit\s+\d+`
text match that hit inside comments, string literals and subqueries. An
inner LIMIT returned 200k rows against a 1,000 cap, into an unbounded
ArrayList and an unvirtualized table.
- Cancel terminates the query instead of only aborting the HTTP request,
which left the statement holding one of the pool's 10 connections. The
client sends an executionId, RunningQueryRegistry maps it to the backend
session pid, and the new cancel endpoint kills exactly that session,
scoped to the connection and the user who started it. The previous UI
behavior killed *every* active query on the connection, including other
users' work.
- Fix pg_terminate_backend binding: setLong sent bigint, so PostgreSQL
found no matching overload and every kill failed, including the Active
Queries screen's own button.
- Editor timeout 600s -> 240s, under nginx's 300s proxy_read_timeout, so
a slow query reports a real error rather than an opaque 504 while still
running.
- Rate-limit /api/connections/*/query (30r/m + burst 20, 429 on reject).
QueryExecutionPolicyServiceTest stubbed isReadOnlyQuery to always return
false — the opposite of what the shipped providers do for WITH — so it
asserted behavior no deployment had, and withInsert_isTreatedAsMutation
passed *because* of the stub. It now uses a real
MySQLQueryExecutionProvider, plus 12 regression tests covering each
bypass and the reads that must keep working.
---------
Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
Co-authored-by: Krishna Sasank Talasila <sasanktk@gmail.com>1 parent 659394f commit 1fbaaf1
18 files changed
Lines changed: 717 additions & 36 deletions
File tree
- backend/src
- main/java/com/dbaagent
- controller
- model
- provider
- api
- mysql
- postgres
- service
- test/java/com/dbaagent/service
- docker/nginx
- src
- components/tabs/Core
- lib/api
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
267 | 267 | | |
268 | 268 | | |
269 | 269 | | |
| 270 | + | |
| 271 | + | |
| 272 | + | |
| 273 | + | |
| 274 | + | |
| 275 | + | |
| 276 | + | |
| 277 | + | |
| 278 | + | |
| 279 | + | |
| 280 | + | |
| 281 | + | |
| 282 | + | |
| 283 | + | |
| 284 | + | |
| 285 | + | |
| 286 | + | |
| 287 | + | |
| 288 | + | |
| 289 | + | |
| 290 | + | |
| 291 | + | |
| 292 | + | |
| 293 | + | |
| 294 | + | |
| 295 | + | |
| 296 | + | |
| 297 | + | |
| 298 | + | |
| 299 | + | |
| 300 | + | |
| 301 | + | |
| 302 | + | |
| 303 | + | |
| 304 | + | |
| 305 | + | |
| 306 | + | |
| 307 | + | |
| 308 | + | |
| 309 | + | |
| 310 | + | |
| 311 | + | |
| 312 | + | |
| 313 | + | |
| 314 | + | |
| 315 | + | |
| 316 | + | |
| 317 | + | |
| 318 | + | |
| 319 | + | |
| 320 | + | |
| 321 | + | |
| 322 | + | |
| 323 | + | |
270 | 324 | | |
271 | 325 | | |
272 | 326 | | |
| |||
Lines changed: 61 additions & 0 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
6 | 6 | | |
7 | 7 | | |
8 | 8 | | |
| 9 | + | |
9 | 10 | | |
| 11 | + | |
10 | 12 | | |
11 | 13 | | |
12 | 14 | | |
| |||
36 | 38 | | |
37 | 39 | | |
38 | 40 | | |
| 41 | + | |
| 42 | + | |
39 | 43 | | |
40 | 44 | | |
41 | 45 | | |
| |||
260 | 264 | | |
261 | 265 | | |
262 | 266 | | |
| 267 | + | |
| 268 | + | |
| 269 | + | |
| 270 | + | |
| 271 | + | |
| 272 | + | |
| 273 | + | |
| 274 | + | |
| 275 | + | |
| 276 | + | |
| 277 | + | |
| 278 | + | |
| 279 | + | |
| 280 | + | |
| 281 | + | |
| 282 | + | |
| 283 | + | |
| 284 | + | |
| 285 | + | |
| 286 | + | |
| 287 | + | |
| 288 | + | |
| 289 | + | |
| 290 | + | |
| 291 | + | |
| 292 | + | |
| 293 | + | |
| 294 | + | |
| 295 | + | |
| 296 | + | |
| 297 | + | |
| 298 | + | |
| 299 | + | |
| 300 | + | |
| 301 | + | |
| 302 | + | |
| 303 | + | |
| 304 | + | |
| 305 | + | |
| 306 | + | |
| 307 | + | |
| 308 | + | |
| 309 | + | |
| 310 | + | |
| 311 | + | |
| 312 | + | |
| 313 | + | |
| 314 | + | |
| 315 | + | |
| 316 | + | |
| 317 | + | |
| 318 | + | |
| 319 | + | |
| 320 | + | |
| 321 | + | |
| 322 | + | |
| 323 | + | |
263 | 324 | | |
264 | 325 | | |
265 | 326 | | |
| |||
Lines changed: 3 additions & 0 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
11 | 11 | | |
12 | 12 | | |
13 | 13 | | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
14 | 17 | | |
15 | 18 | | |
16 | 19 | | |
| |||
Lines changed: 19 additions & 0 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
17 | 17 | | |
18 | 18 | | |
19 | 19 | | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
| 26 | + | |
| 27 | + | |
| 28 | + | |
| 29 | + | |
| 30 | + | |
| 31 | + | |
| 32 | + | |
| 33 | + | |
| 34 | + | |
| 35 | + | |
| 36 | + | |
| 37 | + | |
| 38 | + | |
20 | 39 | | |
Lines changed: 12 additions & 0 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
51 | 51 | | |
52 | 52 | | |
53 | 53 | | |
| 54 | + | |
| 55 | + | |
| 56 | + | |
| 57 | + | |
| 58 | + | |
| 59 | + | |
| 60 | + | |
| 61 | + | |
| 62 | + | |
| 63 | + | |
| 64 | + | |
| 65 | + | |
54 | 66 | | |
Lines changed: 5 additions & 0 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
123 | 123 | | |
124 | 124 | | |
125 | 125 | | |
| 126 | + | |
| 127 | + | |
| 128 | + | |
| 129 | + | |
| 130 | + | |
126 | 131 | | |
Lines changed: 5 additions & 0 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
127 | 127 | | |
128 | 128 | | |
129 | 129 | | |
| 130 | + | |
| 131 | + | |
| 132 | + | |
| 133 | + | |
| 134 | + | |
130 | 135 | | |
Lines changed: 8 additions & 1 deletion
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
203 | 203 | | |
204 | 204 | | |
205 | 205 | | |
| 206 | + | |
| 207 | + | |
| 208 | + | |
| 209 | + | |
| 210 | + | |
| 211 | + | |
| 212 | + | |
206 | 213 | | |
207 | | - | |
| 214 | + | |
208 | 215 | | |
209 | 216 | | |
210 | 217 | | |
| |||
0 commit comments