Skip to content

test(e2e): prove row-level access conditions reach SQLite SQL; bump dalgo to v0.75.1 - #33

Merged
trakhimenok merged 1 commit into
mainfrom
test/dalgo2sqlite-conditions-proof-20260903
Sep 3, 2026
Merged

trakhimenok merged 1 commit into
mainfrom
test/dalgo2sqlite-conditions-proof-20260903

Conversation

@trakhimenok

Copy link
Copy Markdown
Contributor

Bumps dalgo to v0.75.1 and adds TestE2E_AccessConditionsReachSQL: a policy where on Customers narrows a query on this adapter (which emits SQL from the query's String()), the caller's own condition conjoins, a quote inside a literal is escaped, a quote inside a policy variable cannot widen the query, and a missing variable is denied before the adapter runs.

🤖 Generated with Claude Code

https://claude.ai/code/session_01PEVhqasFJJ3iAcARe7Wts6

…algo to v0.75.1

dalgo2sql emits SQL from the query's String(), so a policy residual that
only lived on Where() would have been dropped. With dalgo v0.75.1
(dal.WithWhere + quote escaping) the narrowed query, the conjoined caller
condition, an escaped quote in a literal, a quote inside a policy variable
(returns no rows), and a missing variable (denied) all behave on SQLite.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01PEVhqasFJJ3iAcARe7Wts6
@trakhimenok
trakhimenok merged commit fda7001 into main Sep 3, 2026
3 checks passed
@trakhimenok
trakhimenok deleted the test/dalgo2sqlite-conditions-proof-20260903 branch September 3, 2026 09:58
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant