Files
SuperBizAgent-java/openspec/changes/archive/2026-07-21-single-react-mysql-readonly-tool/tasks.md
T

1.4 KiB

Tasks: single-react-mysql-readonly-tool

1. Security prerequisite and dependency

  • 1.1 Add JSqlParser 4.6 and record the locked parser version.
  • 1.2 Make scripts/query_mysql.py environment-only and read-only; remove commit and unsafe interactive paths.

2. SQL policy and allowlist model

  • 2.1 Implement immutable data-source/allowlist/limit models and validated query plan.
  • 2.2 Implement JSqlParser single-SELECT validator, identifier resolution, function/wildcard/join policy and placeholder count checks.
  • 2.3 Add parser and allowlist security fixtures for accepted/rejected SQL.

3. JDBC executor and projection

  • 3.1 Implement read-only PreparedStatement executor with timeout, max rows, Run cancellation and safe error mapping.
  • 3.2 Implement MysqlResultProjector with row/cell/byte bounds, redaction, JSON-safe values and NO_EVIDENCE.
  • 3.3 Add isolated executor/projector tests for valid rows, empty rows, truncation, sensitive columns and timeout/cancel behavior.

4. ToolBoundary adapter and verification

  • 4.1 Implement typed MySQL adapter through the existing ToolBoundary and canonical invocation store.
  • 4.2 Add adapter tests proving exact framework ID, raw isolation, validation-before-execution and safe errors.
  • 4.3 Run focused compile/tests, validate OpenSpec, update devflow evidence, archive and commit before stage 4.