Skip to content

fix(oceanbase-oracle): escape SQL identifiers and literals in metadata/DDL paths (#1914)#2205

Open
HandSonic wants to merge 4 commits into
OtterMind:mainfrom
HandSonic:fix/sqli2-oceanbase-oracle
Open

fix(oceanbase-oracle): escape SQL identifiers and literals in metadata/DDL paths (#1914)#2205
HandSonic wants to merge 4 commits into
OtterMind:mainfrom
HandSonic:fix/sqli2-oceanbase-oracle

Conversation

@HandSonic

Copy link
Copy Markdown
Contributor

Part of the SQL-injection hardening tracked in #1914. Prior art: #2052 (Oracle), #2053 (SQL Server), and the wave-1 batch (#2172-#2177).

These are second-order injection paths: values such as table/schema/view/index names originate from the connected database's own metadata, so exploitation requires a maliciously named object in a target database.

What changed (6 sites)

Six literal-interpolation sites in OceanbaseOracleMetaData (tableDDL/comments/index DDL) escaped via new OceanbaseOracleSqlEscapes.

Verification

mvn -B -pl chat2db-community-plugins/chat2db-community-oceanbase-oracle -f chat2db-community-server/pom.xml -Dmaven.test.skip=false -DskipTests=false -Dsurefire.includes=**/*Test.java -Dsurefire.failIfNoSpecifiedTests=false -Dmaven.test.failure.ignore=false test

Result: Tests run: 5, Failures: 0, Errors: 0, Skipped: 0.

This branch also passed a two-lens adversarial review (escape-correctness/coverage + regression/test-efficacy); all blocking findings were fixed and re-tested before submission.

…ierProcessor per maintainer review (OtterMind#1914)

- new OceanbaseOracleIdentifierProcessor (SPI ISQLIdentifierProcessor):
  quoteIdentifier with double-quote doubling, escapeString with
  single-quote doubling
- OceanbaseOracleMetaData overrides getSQLIdentifierProcessor(); DDL
  builder helpers use OceanbaseOracleIdentifierProcessor.INSTANCE
- OceanbaseOracleSqlEscapes removed; tests migrated (5 green)
…always-quote for DDL paths (OtterMind#1914)

- quoteIdentifier(String) is conditional again: null/blank passthrough,
  plain non-reserved identifiers returned unquoted (fixes
  GenericSqlCompletionEngine raw-vs-quoted mismatches); other inputs are
  double-quote wrapped with embedded-quote doubling
- new quoteIdentifierAlways(String) for DDL-generation call sites that
  require unconditional quoting; quoteIdentifierIgnoreCase is the
  always-quote SPI variant and delegates to it
- processor now extends OracleIdentifierProcessor to inherit the Oracle
  reserved-keyword set; versioned overload delegates to
  quoteIdentifier(String)
- tests cover conditional and always behaviors incl. null passthrough
  (10 green)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Status: In Review

Development

Successfully merging this pull request may close these issues.

2 participants