Add text-to-sql module: schema prompt through a restricted role, JSqlParser guard, read-only role with column grants and timeout, row cap, execution-based evaluation on a real PostgreSQL

Co-Authored-By: Claude Sonnet 5.5 <[email protected]>
Claude-Session: https://claude.ai/code/session_01JXVi2GMQ7bR5EmbUFdDj7N
This commit is contained in:
Claude
2026-10-09 07:22:28 +00:00
parent d67ac0630b
commit 85a3359186
26 changed files with 1179 additions and 0 deletions
+12
View File
@@ -0,0 +1,12 @@
# What the t2s_reader role can and cannot do
SHOW statement_timeout ok: 2s
SHOW default_transaction_read_only ok: on
SELECT count(*) FROM orders ok: 1000
INSERT INTO orders ... (wall 1: read-only default) ERROR: cannot execute INSERT in a read-only transaction
SELECT set_config('default_transaction_read_only','off',false) ok: off
SHOW default_transaction_read_only ok: off
INSERT INTO orders ... (wall 2: no INSERT privilege) ERROR: permission denied for table orders
SELECT count(*) FROM api_keys ERROR: permission denied for table api_keys
SELECT email FROM customers ERROR: permission denied for table customers
SELECT id, name FROM customers LIMIT 1 ok: 1