- Reject identifiers and directions outside the caller allow-list - Emit ordinary ORDER BY without COLLATE so ICU pl-PL applies Co-authored-by: Cursor <cursoragent@cursor.com>
40 lines
1000 B
Go
40 lines
1000 B
Go
package lagoon
|
|
|
|
import (
|
|
"strings"
|
|
"testing"
|
|
)
|
|
|
|
func TestOrderClauseAllowList(t *testing.T) {
|
|
allowed := []string{"golem15_fonoteka_genres.name", "items.title"}
|
|
|
|
got, err := orderClause("golem15_fonoteka_genres.name", "asc", allowed)
|
|
if err != nil {
|
|
t.Fatal(err)
|
|
}
|
|
if got != "golem15_fonoteka_genres.name ASC" {
|
|
t.Fatalf("got %q", got)
|
|
}
|
|
if strings.Contains(strings.ToLower(got), "collate") {
|
|
t.Fatalf("must not emit COLLATE: %q", got)
|
|
}
|
|
|
|
got, err = orderClause("items.title", "DESC", allowed)
|
|
if err != nil {
|
|
t.Fatal(err)
|
|
}
|
|
if got != "items.title DESC" {
|
|
t.Fatalf("got %q", got)
|
|
}
|
|
|
|
if _, err := orderClause("golem15_fonoteka_genres.name;drop table x", "asc", allowed); err == nil {
|
|
t.Fatal("want reject unknown column")
|
|
}
|
|
if _, err := orderClause("golem15_fonoteka_genres.name", "ascending", allowed); err == nil {
|
|
t.Fatal("want reject unknown direction")
|
|
}
|
|
if _, err := OrderBy(nil, "items.title", "asc", allowed); err == nil {
|
|
t.Fatal("want nil db error")
|
|
}
|
|
}
|