Skip to content
GitLab
Explore
Sign in
Primary navigation
Search or go to…
Project
M
Metabase
Manage
Activity
Members
Labels
Plan
Issues
Issue boards
Milestones
Iterations
Wiki
Requirements
Code
Merge requests
Repository
Branches
Commits
Tags
Repository graph
Compare revisions
Snippets
Locked files
Build
Pipelines
Jobs
Pipeline schedules
Test cases
Artifacts
Deploy
Releases
Package registry
Container Registry
Model registry
Operate
Environments
Terraform modules
Monitor
Incidents
Service Desk
Analyze
Value stream analytics
Contributor analytics
CI/CD analytics
Repository analytics
Code review analytics
Issue analytics
Insights
Model experiments
Help
Help
Support
GitLab documentation
Compare GitLab plans
Community forum
Contribute to GitLab
Provide feedback
Terms and privacy
Keyboard shortcuts
?
Snippets
Groups
Projects
Show more breadcrumbs
Engineering Digital Service
Metabase
Commits
e0c3812a
Unverified
Commit
e0c3812a
authored
2 years ago
by
Cam Saul
Committed by
GitHub
2 years ago
Browse files
Options
Downloads
Patches
Plain Diff
Disallow FDW connections in SQLite (#21525)
parent
88c786dc
No related branches found
No related tags found
No related merge requests found
Changes
2
Hide whitespace changes
Inline
Side-by-side
Showing
2 changed files
modules/drivers/sqlite/src/metabase/driver/sqlite.clj
+3
-1
3 additions, 1 deletion
modules/drivers/sqlite/src/metabase/driver/sqlite.clj
modules/drivers/sqlite/test/metabase/driver/sqlite_test.clj
+28
-1
28 additions, 1 deletion
modules/drivers/sqlite/test/metabase/driver/sqlite_test.clj
with
31 additions
and
2 deletions
modules/drivers/sqlite/src/metabase/driver/sqlite.clj
+
3
−
1
View file @
e0c3812a
...
...
@@ -66,7 +66,9 @@
:as
details
}]
(
merge
{
:subprotocol
"sqlite"
:subname
db
}
(
dissoc
details
:db
)))
(
dissoc
details
:db
)
;; disallow "FDW" (connecting to other SQLite databases on the local filesystem) -- see https://github.com/metabase/metaboat/issues/152
{
:limit_attached
0
}))
;; We'll do regex pattern matching here for determining Field types because SQLite types can have optional lengths,
;; e.g. NVARCHAR(100) or NUMERIC(10,5) See also http://www.sqlite.org/datatype3.html
...
...
This diff is collapsed.
Click to expand it.
modules/drivers/sqlite/test/metabase/driver/sqlite_test.clj
+
28
−
1
View file @
e0c3812a
(
ns
metabase.driver.sqlite-test
(
:require
[
clojure.java.jdbc
:as
jdbc
]
(
:require
[
clojure.java.io
:as
io
]
[
clojure.java.jdbc
:as
jdbc
]
[
clojure.test
:refer
:all
]
[
metabase.driver
:as
driver
]
[
metabase.driver.sql-jdbc.connection
:as
sql-jdbc.conn
]
[
metabase.driver.sql.query-processor-test-util
:as
sql.qp-test-util
]
[
metabase.models.database
:refer
[
Database
]]
[
metabase.models.table
:refer
[
Table
]]
[
metabase.query-processor
:as
qp
]
[
metabase.query-processor-test
:as
qp.test
]
[
metabase.sync
:as
sync
]
[
metabase.test
:as
mt
]
[
metabase.test.data
:as
data
]
[
metabase.test.util
:as
tu
]
[
metabase.util
:as
u
]
[
toucan.db
:as
db
]
[
toucan.hydrate
:refer
[
hydrate
]]))
...
...
@@ -232,3 +235,27 @@
:aggregation
[
:count
]
:order-by
[[
:asc
[
:expression
:CATEGORY
]]]
:limit
1
}))))))))
(
deftest
disallow-fdw-to-other-databases-test
(
testing
"Don't allow connections to other SQLite databases with ATTACH DATABASE (https://github.com/metabase/metaboat/issues/152)"
(
mt/test-driver
:sqlite
;; force creation of the sample dataset file
(
mt/dataset
sample-dataset
(
mt/id
))
(
let
[
file
(
io/file
"sample-dataset.sqlite"
)
path
(
.getAbsolutePath
file
)]
(
is
(
.exists
file
))
(
testing
"Attach the sample dataset as an FDW called fdw_test"
(
testing
"Detach it if it already exists from a previous test run"
(
u/ignore-exceptions
(
qp/process-query
(
mt/native-query
{
:query
"DETACH DATABASE fdw_test;"
}))))
(
testing
"Attempting to attach it should fail"
(
is
(
thrown-with-msg?
clojure.lang.ExceptionInfo
#
"SQL error or missing database \(too many attached databases - max 0\)"
(
qp/process-query
(
mt/native-query
{
:query
(
format
"ATTACH DATABASE 'file:%s' as fdw_test;"
path
)}))))))
(
testing
"Attempt to query the FDW -- shouldn't work"
(
is
(
thrown-with-msg?
clojure.lang.ExceptionInfo
#
"SQL error or missing database \(no such table: fdw_test\.products\)"
(
qp/process-query
(
mt/native-query
{
:query
"SELECT count(*) FROM fdw_test.products;"
})))))))))
This diff is collapsed.
Click to expand it.
Preview
0%
Loading
Try again
or
attach a new file
.
Cancel
You are about to add
0
people
to the discussion. Proceed with caution.
Finish editing this message first!
Save comment
Cancel
Please
register
or
sign in
to comment