feat(harness): add readonly mysql tool
This commit is contained in:
@@ -0,0 +1,24 @@
|
||||
# Tasks: single-react-mysql-readonly-tool
|
||||
|
||||
## 1. Security prerequisite and dependency
|
||||
|
||||
- [x] 1.1 Add JSqlParser 4.6 and record the locked parser version.
|
||||
- [x] 1.2 Make `scripts/query_mysql.py` environment-only and read-only; remove commit and unsafe interactive paths.
|
||||
|
||||
## 2. SQL policy and allowlist model
|
||||
|
||||
- [x] 2.1 Implement immutable data-source/allowlist/limit models and validated query plan.
|
||||
- [x] 2.2 Implement JSqlParser single-SELECT validator, identifier resolution, function/wildcard/join policy and placeholder count checks.
|
||||
- [x] 2.3 Add parser and allowlist security fixtures for accepted/rejected SQL.
|
||||
|
||||
## 3. JDBC executor and projection
|
||||
|
||||
- [x] 3.1 Implement read-only PreparedStatement executor with timeout, max rows, Run cancellation and safe error mapping.
|
||||
- [x] 3.2 Implement `MysqlResultProjector` with row/cell/byte bounds, redaction, JSON-safe values and `NO_EVIDENCE`.
|
||||
- [x] 3.3 Add isolated executor/projector tests for valid rows, empty rows, truncation, sensitive columns and timeout/cancel behavior.
|
||||
|
||||
## 4. ToolBoundary adapter and verification
|
||||
|
||||
- [x] 4.1 Implement typed MySQL adapter through the existing ToolBoundary and canonical invocation store.
|
||||
- [x] 4.2 Add adapter tests proving exact framework ID, raw isolation, validation-before-execution and safe errors.
|
||||
- [x] 4.3 Run focused compile/tests, validate OpenSpec, update devflow evidence, archive and commit before stage 4.
|
||||
Reference in New Issue
Block a user