1.9 KiB
1.9 KiB
Evidence: single-react-mysql-readonly-tool
Static verification
git diff --check: passed before archive.- Security scan confirms the query helper has no default external host/port/root user and no
commit()write path. - New MySQL Harness code receives only injected logical DataSources and does not reference
spring.datasourceor the application persistence datasource. - OpenSpec strict validation passed for
single-react-mysql-readonly-tool.
Script/build verification
mvn -q -DskipTests compile: passed.- Focused suite passed:
MysqlSqlValidatorTest,MysqlResultProjectorTest,JdbcMysqlReadOnlyExecutorTest,MysqlToolAdapterTest,MysqlToolContractTest,ToolBoundaryTest,CanonicalInvocationStoreTest. - Python syntax compilation passed for
scripts/query_mysql.py. - Missing connection environment variables exit before connection with code 2.
- A write SQL invocation is rejected before connection with code 3.
Security coverage
- Allowed: explicit allowlisted SELECT, parameter placeholders, qualified INNER JOIN and
COUNT(*). - Rejected: write, WITH, subquery, UNION, wildcard projection, unknown table/column, ambiguous column, dangerous function, inline literal, CASE, FOR UPDATE, multi-statement and placeholder mismatch.
- JDBC controls verified:
setReadOnly(true),PreparedStatement,setQueryTimeout,setMaxRows, ordered parameter binding and cancellation-before-execution. - Projection controls verified: max rows, max cell chars, total UTF-8 bytes, sensitive-column redaction, valid bounded JSON and
NO_EVIDENCE.
Not verified in this stage
- No live production business datasource was provisioned or queried; ISS-014 explicitly assigns live E2E to a later issue/stage.
- No public Diagnosis Agent/Chat integration was performed; stage 4 will consume the adapter internally.
- JDBC driver timeout/cancel behavior against a real remote MySQL server remains an operational integration risk.