postgres: the store's query runs as a read-only login, never as the admin (hq #193)

The verb wrapped the caller's text in BEGIN READ ONLY ... ROLLBACK as the superuser, so
'COMMIT; ...' left the transaction and, proven on a throwaway server, COPY TO PROGRAM ran a
shell command on the database host. The statement now runs as mesh_store_reader:
pg_read_all_data, no other grant, read-only transactions by role and session, its password
an own-secret the mesh mints. Without that password the call is refused. -q drops the
command tags that came back as rows keyed by BEGIN.
This commit is contained in:
2026-10-02 00:09:09 +02:00
parent ef44c502db
commit 160b5ad65a
5 changed files with 204 additions and 10 deletions
+1 -1
View File
@@ -16,7 +16,7 @@ export function getPostgresTools(postgres: PostgresClient): ToolDefinition[] {
},
{
name: "postgres_query",
description: "Run a read-only SQL query against a named database (wrapped in a read-only transaction).",
description: "Run a read-only SQL query against a named database, as a login that can read every table and change nothing.",
input: {
database: { type: "string", description: "the database to query" },
sql: { type: "string", description: "the SELECT (or other read-only) statement" },