Commit Graph

5 Commits

Author SHA1 Message Date
Egor Bugaev ca0605706f Security hardening round 2: comment-aware forbidden-pattern check, UPDATE confirmation, transactional batches, quote-aware split (incl. double quotes), NULL-safe table rendering, AJAX timeout, request size limit
- removeAllComments() strips -- and /* */ comments before checking
  FORBIDDEN_PATTERNS, closing a bypass where a comment inserted between
  a function name and '(' hid it from the regex (e.g. pg_read_file/**/(...)).
- UPDATE now requires confirm=true just like DELETE (deleteCount/updateCount).
- Batches run inside a single DB transaction; a failing statement rolls back
  everything already applied in that batch instead of leaving partial writes.
- splitStatements() (PHP and JS) now tracks a single quoteChar instead of a
  bool, handling both '...' strings and "..." quoted identifiers symmetrically.
- Frontend TEMPLATES no longer rely on SET/current_setting: the escaped uid
  is inlined into every statement, so partial copy/paste still works.
- renderTable() renders NULL as [NULL] instead of an empty string, so it's
  no longer visually identical to an empty string value.
- Added MAX_SQL_BYTES (1MB) request size limit, returned as HTTP 413.
- Added a 120s client-side AJAX timeout with a distinct timeout message,
  so a hung request doesn't leave the terminal paused indefinitely.
2026-07-06 19:38:25 +03:00
Egor Bugaev 8aaab998a1 Harden SQL mode: block file/program access, audit log, row limit, quote-aware statement splitting 2026-07-06 17:54:36 +03:00
Egor Bugaev 4d87deb176 Require explicit confirmation before running DELETE statements in SQL mode 2026-07-06 17:03:51 +03:00
fanategorius c1d9494414 Update DbController.php 2026-07-06 16:29:09 +03:00
fanategorius f612931480 Create DbController.php 2026-07-06 12:47:24 +03:00