feat: protect sensitive catalog samples

This commit is contained in:
Codex
2026-08-30 12:14:23 +02:00
parent 6278ee9d81
commit 0736983bc5
28 changed files with 1162 additions and 128 deletions
@@ -92,6 +92,34 @@ test("samples at most five source rows and five distinct non-null examples in a
expect(end).toHaveBeenCalledOnce();
});
test("does not issue a SELECT when a protected target has no source columns", async () => {
const query = vi.fn(async () => ({ rows: [] }));
const end = vi.fn(async () => undefined);
const access: CatalogPostgresAccess = {
connect: vi.fn(async () => ({ query, end }) as CatalogDatabaseClient),
};
const sampler = new PostgresDescriptionSourceSampler(access);
const samples = await sampler.sample(database, [{
targetId: target.targetId,
tableName: target.tableName,
columnNames: [],
}], new AbortController().signal);
expect(samples).toEqual([{
targetId: target.targetId,
tableName: target.tableName,
rows: [],
representativeValues: [],
}]);
expect(query.mock.calls).toEqual([
["BEGIN TRANSACTION READ ONLY", []],
["ROLLBACK", []],
]);
expect(query.mock.calls.some(([sql]) => String(sql).startsWith("SELECT"))).toBe(false);
expect(end).toHaveBeenCalledOnce();
});
test("rolls back and closes the source connection when sampling fails", async () => {
const query = vi.fn(async (sql: string) => {
if (sql.startsWith("SELECT")) throw new Error("distinctive-source-secret");