Commit Graph

2 Commits

Author SHA1 Message Date
can1357 cafa86a6cf fix(tools/sqlite): reject comments, terminators, and pagination keywords in where=
The structured SQLite helper interpolates `where=` directly into SQL.
A crafted clause like `where=1=1 LIMIT 1000000 --` could comment out
the helper's bound `LIMIT ? OFFSET ?`, returning the full table in
violation of the documented pagination contract.

Validate where= at the selector boundary and reject SQL comments,
statement terminators, and pagination/attach/pragma keywords. Raw SQL
remains available via ?q=SELECT... for callers that need it.

Fixes #735
2026-04-24 06:33:20 +02:00
can1357 2cd8f52f4e feat(tools): added SQLite database operations with read/write support and query validation
- Added SQLite path parsing and candidate validation for `.sqlite`, `.db`, `.db3`, and `.sqlite3` targets in read/write flows.
- Added SQLite read operations for table lists, schema views, row lookups, paginated queries, and raw SELECT mode.
- Added SQLite write operations for insert, update-by-key, and delete-by-key using JSON5 row payloads.
- Updated selector routing to validate SQLite headers and fall back to normal file reads/writes when not databases.
- Secured read mode by enforcing query validation to block destructive SQL execution on SQLite inputs.
2026-04-11 08:57:58 +02:00