Add text-to-sql module: schema prompt through a restricted role, JSqlParser guard, read-only role with column grants and timeout, row cap, execution-based evaluation on a real PostgreSQL
Co-Authored-By: Claude Sonnet 5.5 <[email protected]> Claude-Session: https://claude.ai/code/session_01JXVi2GMQ7bR5EmbUFdDj7N
This commit is contained in:
@@ -0,0 +1,12 @@
|
||||
# What the t2s_reader role can and cannot do
|
||||
|
||||
SHOW statement_timeout ok: 2s
|
||||
SHOW default_transaction_read_only ok: on
|
||||
SELECT count(*) FROM orders ok: 1000
|
||||
INSERT INTO orders ... (wall 1: read-only default) ERROR: cannot execute INSERT in a read-only transaction
|
||||
SELECT set_config('default_transaction_read_only','off',false) ok: off
|
||||
SHOW default_transaction_read_only ok: off
|
||||
INSERT INTO orders ... (wall 2: no INSERT privilege) ERROR: permission denied for table orders
|
||||
SELECT count(*) FROM api_keys ERROR: permission denied for table api_keys
|
||||
SELECT email FROM customers ERROR: permission denied for table customers
|
||||
SELECT id, name FROM customers LIMIT 1 ok: 1
|
||||
Reference in New Issue
Block a user