https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=42585 --- Comment #14 from Kyle M Hall (khall) <kyle@bywatersolutions.com> --- Created attachment 207237 --> https://bugs.koha-community.org/bugzilla3/attachment.cgi?id=207237&action=edit Bug 42585: Add safety analyzers Koha won't run a saved report that fails its is_sql_valid whitelist, but the librarian doesn't find out until they click Run and the report errors out. This patch adds three checks that report the same problems while the SQL is being written: forbidden_statement, missing_select and forbidden_column. forbidden_column covers both of the ways Koha refuses a report. The first is a forbidden column named in the SQL, which is_sql_valid catches from the text. The second is one that only shows up in the result set, which Koha catches from the names of the columns it got back, after the query has already run. That's why "SELECT * FROM borrowers" saves happily, runs, and only then says "Illegal column in results". The check expands the wildcards against the schema so the librarian hears about it while they're still writing the report. Test Plan: 1) Apply this patch 2) prove -r t/Koha/Reports/Analyzer/Check/Safety/ \ t/db_dependent/Koha/Reports/Analyzer.t 3) In a koha-shell, run: perl -MKoha::Reports::Analyzer=analyze -MData::Dumper -e \ 'print Dumper analyze({ sql => "UPDATE borrowers SET surname=1" })' 4) Note the forbidden_statement finding with severity high! 5) Repeat with "SELECT password FROM borrowers", note forbidden_column! 6) Repeat with "SELECT * FROM borrowers", note forbidden_column names borrowers.password even though the SQL never mentions it! 7) Save that same report and run it, note Koha refuses it with "Illegal column in results", which is what the finding warned about! 8) Repeat with "SELECT borrowernumber FROM borrowers LIMIT 1", note the empty findings list! -- You are receiving this mail because: You are watching all bug changes.