mssql: the query runs as a read-only login, one line, no variables; sqlcmd is installed (hq #193)
Proven on a throwaway server: as the administrator a caller's $(SQLCMDPASSWORD) returned the sa password, and a line beginning ':!!' ran a program in the tools container. The statement now runs as mesh_mssql_reader (CONNECT ANY DATABASE, SELECT ALL USER SECURABLES), with substitution off (-x), after the module's own text on the first line, and a line break is refused. go-sqlcmd v1.10.0 is installed at a pinned digest: the image never had sqlcmd, so every mssql tool failed with spawn sqlcmd ENOENT.
This commit is contained in:
@@ -16,7 +16,7 @@ export function getMssqlTools(mssql: MssqlClient): ToolDefinition[] {
|
||||
},
|
||||
{
|
||||
name: "mssql_query",
|
||||
description: "Run a read-only SELECT against a named database (wrapped in a rolled-back transaction).",
|
||||
description: "Run a read-only SELECT against a named database, as a login that can read every table and change nothing.",
|
||||
input: {
|
||||
database: { type: "string", description: "the database to query" },
|
||||
sql: { type: "string", description: "a single SELECT statement" },
|
||||
|
||||
Reference in New Issue
Block a user