https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=42585

--- Comment #14 from Kyle M Hall (khall) <[email protected]> ---
Created attachment 207237
  -->
https://bugs.koha-community.org/bugzilla3/attachment.cgi?id=207237&action=edit
Bug 42585: Add safety analyzers

Koha won't run a saved report that fails its is_sql_valid whitelist,
but the librarian doesn't find out until they click Run and the report
errors out.

This patch adds three checks that report the same problems while the
SQL is being written: forbidden_statement, missing_select and
forbidden_column.

forbidden_column covers both of the ways Koha refuses a report. The
first is a forbidden column named in the SQL, which is_sql_valid
catches from the text. The second is one that only shows up in the
result set, which Koha catches from the names of the columns it got
back, after the query has already run. That's why "SELECT * FROM
borrowers" saves happily, runs, and only then says "Illegal column in
results". The check expands the wildcards against the schema so the
librarian hears about it while they're still writing the report.

Test Plan:
1) Apply this patch
2) prove -r t/Koha/Reports/Analyzer/Check/Safety/ \
         t/db_dependent/Koha/Reports/Analyzer.t
3) In a koha-shell, run:
   perl -MKoha::Reports::Analyzer=analyze -MData::Dumper -e \
     'print Dumper analyze({ sql => "UPDATE borrowers SET surname=1" })'
4) Note the forbidden_statement finding with severity high!
5) Repeat with "SELECT password FROM borrowers", note forbidden_column!
6) Repeat with "SELECT * FROM borrowers", note forbidden_column names
   borrowers.password even though the SQL never mentions it!
7) Save that same report and run it, note Koha refuses it with
   "Illegal column in results", which is what the finding warned about!
8) Repeat with "SELECT borrowernumber FROM borrowers LIMIT 1", note the
   empty findings list!

-- 
You are receiving this mail because:
You are watching all bug changes.
_______________________________________________
Koha-bugs mailing list -- [email protected]
To unsubscribe send an email to [email protected]
website : http://www.koha-community.org/
git : http://git.koha-community.org/
bugs : http://bugs.koha-community.org/

Reply via email to