Skip to content

fix(dispatch): remove /test_db prototype endpoint - #232

Merged
ZhuchkaTriplesix merged 1 commit into
devfrom
issue-210-remove-test-db-endpoint
Sep 29, 2026
Merged

ZhuchkaTriplesix merged 1 commit into
devfrom
issue-210-remove-test-db-endpoint

Conversation

@ZhuchkaTriplesix

Copy link
Copy Markdown
Member

Problem

GET /test_db was a hardcoded benchmark prototype (issue #55) still present in the hot path (both the sync short-circuit and the async run_rsgi handler). If a DB pool was configured:

  • it silently shadowed any user-registered route at that exact path, and
  • on query error it returned the raw sqlx error string via format! without escaping — leaks backend detail (host, auth failure text) and is a JSON-injection risk if the error text contains quotes.

Fix

Removed both code paths entirely. FrozenState.db_pool was only ever read by this endpoint, so the now-dead field was dropped along with it — the dependency-injected DBQuery execution path reads AppState.db_pool directly (a different field) and is unaffected.

Testing

  • cargo build --lib: clean, no warnings.
  • cargo clippy --all-targets: clean.
  • cargo test --lib: 26 passed.
  • maturin develop --release + full suite: 164 passed, 1 skipped.
  • No docs reference /test_db.

Closes #210

GET /test_db was a hardcoded benchmark prototype (issue #55) left in
the hot path. If a DB pool was configured it silently shadowed any
user-registered route at that exact path, and on query error it
returned the raw sqlx error string assembled via format! without
escaping - a backend detail leak and a JSON-injection risk if the
error text contained quotes.

Removed both the sync short-circuit bailout and the async handler.
FrozenState.db_pool was only read by this endpoint - dropped the now-
dead field along with it; dependency-injected DBQuery execution reads
AppState.db_pool directly and is unaffected.

Closes #210
@ZhuchkaTriplesix
ZhuchkaTriplesix merged commit a77aad6 into dev Sep 29, 2026
17 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant