Skip to content

fix(security): prevent Safe Mode precheck bypass on multi-statement SQL queries - #65

Merged
ZhuchkaTriplesix merged 1 commit into
devfrom
issue/54-safe-mode-multi-statement
Sep 27, 2026
Merged

ZhuchkaTriplesix merged 1 commit into
devfrom
issue/54-safe-mode-multi-statement

Conversation

@ZhuchkaTriplesix

Copy link
Copy Markdown
Member

Summary

  • Implemented split_sql_statements parser that correctly splits SQL by ; outside quotes and comments
  • Masked string literal contents in strip_sql_comments_and_trim to prevent false positives from string contents while preserving identifiers
  • Updated enforce_safe_mode_precheck to evaluate each statement in multi-statement queries individually, blocking any destructive statements
  • Added unit tests for SQL statement splitting and multi-statement Safe Mode bypass attempts

Closes #54

@ZhuchkaTriplesix
ZhuchkaTriplesix merged commit 751393e into dev Sep 27, 2026
2 checks passed
@ZhuchkaTriplesix
ZhuchkaTriplesix deleted the issue/54-safe-mode-multi-statement branch September 27, 2026 21:08
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant