Skip to content

fix: enforce read-only execution in SQL example - #18

Merged
fitz2882 merged 1 commit into
mainfrom
codex/security-remediation-sql
Sep 5, 2026
Merged

fix: enforce read-only execution in SQL example#18
fitz2882 merged 1 commit into
mainfrom
codex/security-remediation-sql

Conversation

@fitz2882

@fitz2882 fitz2882 commented Sep 5, 2026

Copy link
Copy Markdown
Contributor

The SQL example previously relied on statement-prefix filtering, which did not enforce read-only execution. Install an SQLite authorizer that permits reads and denies state-changing operations, with query_only enabled after fixture setup. Valid SELECT, CTE, recursive, and window queries retain their behavior.

Validation: 133 focused tests pass, including nine new SQLite tests; four regressions fail against the previous source. Tests use disposable in-memory fixtures with no model or telemetry calls. Fresh independent review approved the final commit and all 11 CI jobs passed. Runtime resource exhaustion is outside this fixture-mutation fix.

@fitz2882
fitz2882 marked this pull request as ready for review September 5, 2026 13:52
@fitz2882
fitz2882 merged commit 8579ee9 into main Sep 5, 2026
11 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant