Skip to content

Correção dos bugs 1 e 2 (blacklist SQL e data exploration) - #16

Merged
Fugant1 merged 1 commit into
gruporaia:devfrom
antoniocaarvalh:fix/blocklist-outfile-and-exploration-skip
Oct 6, 2026
Merged

Fugant1 merged 1 commit into
gruporaia:devfrom
antoniocaarvalh:fix/blocklist-outfile-and-exploration-skip

Conversation

@antoniocaarvalh

@antoniocaarvalh antoniocaarvalh commented Oct 5, 2026 •

Copy link
Copy Markdown
Collaborator

Corrige dois problemas que ficaram do suporte a Postgres/MySQL.

Correçao da blacklist e de pular o no de exploraçao

… non-SQLite backends

- validar_sql_segura: block the standalone OUTFILE/DUMPFILE keywords instead of
  matching the phrase "INTO\s+OUTFILE". MySQL accepts comments between the two
  words (INTO/**/OUTFILE, INTO /*!50000 OUTFILE*/, or a -- / # line comment
  followed by a newline), so whitespace-only matching let a SELECT that writes
  a file on the server slip past the read-only check. Verified against a real
  MySQL 8.4: all five variants parse as valid syntax.
- nos_nodo_data_exploration: skip when the configured backend is not a local
  SQLite file (db_url set, or db_dialeto / db_path extension is not sqlite).
  The node only knows how to open db_path with sqlite3, and the CLI leaves
  db_path at a default .db file, so a Postgres/MySQL run would silently explore
  that unrelated file and feed the LLM statistics from the wrong database.
- Regression tests for every bypass variant, for legitimate queries that must
  keep passing, and for each skip case of the exploration node.
@Fugant1 Fugant1 self-assigned this Oct 6, 2026
@Fugant1
Fugant1 merged commit c093b68 into gruporaia:dev Oct 6, 2026
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants