From 1b277fc661f99405e540099b8ab2387d4cf8580c Mon Sep 17 00:00:00 2001 From: ZhuchkaTriplesix Date: Tue, 29 Sep 2026 13:11:51 +0300 Subject: [PATCH] fix(dispatch): remove /test_db prototype endpoint GET /test_db was a hardcoded benchmark prototype (issue #55) left in the hot path. If a DB pool was configured it silently shadowed any user-registered route at that exact path, and on query error it returned the raw sqlx error string assembled via format! without escaping - a backend detail leak and a JSON-injection risk if the error text contained quotes. Removed both the sync short-circuit bailout and the async handler. FrozenState.db_pool was only read by this endpoint - dropped the now- dead field along with it; dependency-injected DBQuery execution reads AppState.db_pool directly and is unaffected. Closes #210 --- src/dispatch.rs | 32 -------------------------------- src/state.rs | 3 --- 2 files changed, 35 deletions(-) diff --git a/src/dispatch.rs b/src/dispatch.rs index f8a64b3..0abc15a 100644 --- a/src/dispatch.rs +++ b/src/dispatch.rs @@ -355,9 +355,6 @@ pub fn try_rsgi_sync_short_circuit( if !snapshot.request_middleware.is_empty() || !snapshot.response_middleware.is_empty() { return Ok(None); } - if method == "GET" && path == "/test_db" { - return Ok(None); // defer to async run_rsgi for the prototype - } if (method == "GET" || method == "HEAD") && path == "/openapi.json" && snapshot.include_openapi { let _ = protocol_py.setattr(py, "__oxyroute_path_template__", "/openapi.json"); @@ -503,35 +500,6 @@ pub async fn run_rsgi( } return response::send_str(&protocol, 200, &doc, "application/json; charset=utf-8").await; } - // Prototype: Issue 55 (sqlx integration benchmark path) - if method == "GET" && path == "/test_db" { - let _ = - Python::with_gil(|py| protocol.setattr(py, "__oxyroute_path_template__", "/test_db")); - if let Some(pool) = snapshot.db_pool.as_ref() { - use sqlx::Row; - match sqlx::query("SELECT 1 as num").fetch_one(pool).await { - Ok(row) => { - let num: i32 = row.get("num"); - return response::send_str( - &protocol, - 200, - &format!(r#"{{"num":{num}}}"#), - "application/json; charset=utf-8", - ) - .await; - } - Err(e) => { - return response::send_str( - &protocol, - 500, - &format!(r#"{{"error":"{e}"}}"#), - "application/json; charset=utf-8", - ) - .await; - } - } - } - } for mw in snapshot.request_middleware.iter() { let out: Py = match Python::with_gil(|py| { let f = mw.bind(py); diff --git a/src/state.rs b/src/state.rs index 06194dc..dd94f92 100644 --- a/src/state.rs +++ b/src/state.rs @@ -205,7 +205,6 @@ impl AppState { response_middleware: Arc::clone(&response_middleware), exception_handlers: Arc::clone(&exception_handlers), include_openapi: true, - db_pool: None, }); Self { routes, @@ -248,7 +247,6 @@ impl AppState { response_middleware: Arc::clone(&self.response_middleware), exception_handlers: Arc::clone(&self.exception_handlers), include_openapi: self.include_openapi, - db_pool: self.db_pool.clone(), }); }); } @@ -290,7 +288,6 @@ pub struct FrozenState { pub response_middleware: Arc>>, pub exception_handlers: ExceptionHandlerList, pub include_openapi: bool, - pub db_pool: Option, } pub type HotSnapshot = Arc;