fix(dispatch): remove /test_db prototype endpoint - #232
Merged
Merged
Conversation
GET /test_db was a hardcoded benchmark prototype (issue #55) left in the hot path. If a DB pool was configured it silently shadowed any user-registered route at that exact path, and on query error it returned the raw sqlx error string assembled via format! without escaping - a backend detail leak and a JSON-injection risk if the error text contained quotes. Removed both the sync short-circuit bailout and the async handler. FrozenState.db_pool was only read by this endpoint - dropped the now- dead field along with it; dependency-injected DBQuery execution reads AppState.db_pool directly and is unaffected. Closes #210
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
GET /test_dbwas a hardcoded benchmark prototype (issue #55) still present in the hot path (both the sync short-circuit and the asyncrun_rsgihandler). If a DB pool was configured:format!without escaping — leaks backend detail (host, auth failure text) and is a JSON-injection risk if the error text contains quotes.Fix
Removed both code paths entirely.
FrozenState.db_poolwas only ever read by this endpoint, so the now-dead field was dropped along with it — the dependency-injectedDBQueryexecution path readsAppState.db_pooldirectly (a different field) and is unaffected.Testing
cargo build --lib: clean, no warnings.cargo clippy --all-targets: clean.cargo test --lib: 26 passed.maturin develop --release+ full suite: 164 passed, 1 skipped./test_db.Closes #210