Escape the database path in the SQLite connection string (closes #55)
check / check (push) Failing after 2s
check / check (push) Failing after 2s
openDB put the path into the connection string unescaped, so a ? or # in it ended the file name and a % started an escape: scan could silently fill a database under a shortened name. The path now goes through net/url as a file: URI. An absolute path gets an empty host and a relative path none, because SQLite reads what follows file:// up to the next slash as a host name. The path is not cleaned, so it stays exactly what the operator gave. A test runs scan, report and trees against such a file name given as an absolute path, as one starting with //, and as a relative path, and checks that only that file and its lock file exist afterwards. Model: opus-5-5
This commit was merged in pull request #87.
This commit is contained in:
@@ -6,6 +6,7 @@ import (
|
||||
"errors"
|
||||
"fmt"
|
||||
"io/fs"
|
||||
"net/url"
|
||||
"os"
|
||||
"path/filepath"
|
||||
"slices"
|
||||
@@ -107,7 +108,19 @@ const reportParams = "mode=ro" +
|
||||
// openDB opens the SQLite database at path with the connection
|
||||
// parameters params. It does not create or verify the schema.
|
||||
func openDB(path, params string) (*sql.DB, error) {
|
||||
db, err := sql.Open("sqlite", "file:"+path+"?"+params)
|
||||
// The path is escaped into a file: URI, so ?, # and % in it stay
|
||||
// part of the file name. SQLite reads what follows file:// up to
|
||||
// the next / as a host name, so an absolute path goes after an
|
||||
// empty host (file:///abs) and a relative path goes without one
|
||||
// (file:rel).
|
||||
uri := url.URL{
|
||||
Scheme: "file",
|
||||
OmitHost: !filepath.IsAbs(path),
|
||||
Path: path,
|
||||
RawQuery: params,
|
||||
}
|
||||
|
||||
db, err := sql.Open("sqlite", uri.String())
|
||||
if err != nil {
|
||||
return nil, fmt.Errorf("open database %s: %w", path, err)
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user