https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=42585 --- Comment #15 from Kyle M Hall (khall) <kyle@bywatersolutions.com> --- Created attachment 207238 --> https://bugs.koha-community.org/bugzilla3/attachment.cgi?id=207238&action=edit Bug 42585: Add REST API for report analysis This patch adds POST /api/v1/reports/analyze, which runs the analyzer over the given SQL and returns the severity and findings as JSON. It takes the SQL and any placeholder parameters, and is guarded by the reports.create_reports permission. Alongside the findings the response carries the EXPLAIN plan and estimated_rows, the row estimate the runner sized its warnings against. A finding the runner set aside comes back with suppressed set and the reason, so the caller can show it without counting it towards the severity. Test Plan: 1) Apply this patch 2) yarn api:bundle 3) Restart all the things! 4) prove t/db_dependent/api/v1/reports_analyze.t 5) Run: curl -s -X POST \ "http://koha:koha@kohadev-intra.localhost/api/v1/reports/analyze" \ -H "Content-Type: application/json" \ -d '{"sql":"UPDATE borrowers SET surname=1"}' | jq . 6) Note the forbidden_statement finding with severity high! 7) Repeat with "SELECT borrowernumber FROM borrowers LIMIT 1", note the empty findings list and a null severity! 8) Repeat with "SELECT borrowernumber FROM borrowers WHERE borrowernumber = 1 ORDER BY RAND()", note the order_by_rand finding comes back with "suppressed": 1, the reason why, and a null severity! -- You are receiving this mail because: You are watching all bug changes.