Skip to content

test(mcp): values and comments in unexpected places are refused by the matching rule (#1231) - #1233

Merged
ZhuchkaTriplesix merged 1 commit into
devfrom
test/1231-argument-placement
Oct 9, 2026
Merged

ZhuchkaTriplesix merged 1 commit into
devfrom
test/1231-argument-placement

Conversation

@ZhuchkaTriplesix

Copy link
Copy Markdown
Member

Refs #1231

What was missing

The security suite covered statement shapes. Writes that hide where a shape check does not look were not covered: behind a comment, inside a dollar quote, in a CTE, in an executable MySQL comment, or in a row lock at the end of a read.

Changes

  • Six placement cases, each asserting the rule that refuses it: single_statement (a comment does not hide a separator; a dollar-quoted block does not either), data_modifying (a DELETE in a CTE), mysql_executable_comment, and select_into_or_lock.
  • A control: a write keyword inside a string literal stays a value and is not refused.

Not in this PR

  • Argument placements through the tool arguments other than sql (table names are checked against the catalog already).
  • The rule ids in the Settings activity view.

Not verified locally

Tests were not run locally, per the project rule. The rule ids of the first five cases are the ones the guard tests in #1232 already exercise in CI.

…e matching rule (#1231)

Statement-shape cases do not cover writes that hide inside comments, dollar
quotes, a CTE or an executable comment. Each case now asserts the rule that
refuses it, and a write keyword inside a string literal is checked to stay a
value.
@github-actions github-actions Bot added enhancement New feature or request tests Theme parser epic P2 Medium priority / Parity & Refactoring labels Oct 9, 2026
@ZhuchkaTriplesix
ZhuchkaTriplesix merged commit 16a913e into dev Oct 9, 2026
13 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancement New feature or request P2 Medium priority / Parity & Refactoring tests Theme parser epic

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant