1.4 KiB
1.4 KiB
Tasks: single-react-mysql-readonly-tool
1. Security prerequisite and dependency
- 1.1 Add JSqlParser 4.6 and record the locked parser version.
- 1.2 Make
scripts/query_mysql.pyenvironment-only and read-only; remove commit and unsafe interactive paths.
2. SQL policy and allowlist model
- 2.1 Implement immutable data-source/allowlist/limit models and validated query plan.
- 2.2 Implement JSqlParser single-SELECT validator, identifier resolution, function/wildcard/join policy and placeholder count checks.
- 2.3 Add parser and allowlist security fixtures for accepted/rejected SQL.
3. JDBC executor and projection
- 3.1 Implement read-only PreparedStatement executor with timeout, max rows, Run cancellation and safe error mapping.
- 3.2 Implement
MysqlResultProjectorwith row/cell/byte bounds, redaction, JSON-safe values andNO_EVIDENCE. - 3.3 Add isolated executor/projector tests for valid rows, empty rows, truncation, sensitive columns and timeout/cancel behavior.
4. ToolBoundary adapter and verification
- 4.1 Implement typed MySQL adapter through the existing ToolBoundary and canonical invocation store.
- 4.2 Add adapter tests proving exact framework ID, raw isolation, validation-before-execution and safe errors.
- 4.3 Run focused compile/tests, validate OpenSpec, update devflow evidence, archive and commit before stage 4.