feat: protect sensitive catalog samples
This commit is contained in:
@@ -92,6 +92,34 @@ test("samples at most five source rows and five distinct non-null examples in a
|
||||
expect(end).toHaveBeenCalledOnce();
|
||||
});
|
||||
|
||||
test("does not issue a SELECT when a protected target has no source columns", async () => {
|
||||
const query = vi.fn(async () => ({ rows: [] }));
|
||||
const end = vi.fn(async () => undefined);
|
||||
const access: CatalogPostgresAccess = {
|
||||
connect: vi.fn(async () => ({ query, end }) as CatalogDatabaseClient),
|
||||
};
|
||||
const sampler = new PostgresDescriptionSourceSampler(access);
|
||||
|
||||
const samples = await sampler.sample(database, [{
|
||||
targetId: target.targetId,
|
||||
tableName: target.tableName,
|
||||
columnNames: [],
|
||||
}], new AbortController().signal);
|
||||
|
||||
expect(samples).toEqual([{
|
||||
targetId: target.targetId,
|
||||
tableName: target.tableName,
|
||||
rows: [],
|
||||
representativeValues: [],
|
||||
}]);
|
||||
expect(query.mock.calls).toEqual([
|
||||
["BEGIN TRANSACTION READ ONLY", []],
|
||||
["ROLLBACK", []],
|
||||
]);
|
||||
expect(query.mock.calls.some(([sql]) => String(sql).startsWith("SELECT"))).toBe(false);
|
||||
expect(end).toHaveBeenCalledOnce();
|
||||
});
|
||||
|
||||
test("rolls back and closes the source connection when sampling fails", async () => {
|
||||
const query = vi.fn(async (sql: string) => {
|
||||
if (sql.startsWith("SELECT")) throw new Error("distinctive-source-secret");
|
||||
|
||||
Reference in New Issue
Block a user