Add a new `/dbapi` router package providing a generic database API over `dataset`, restricted to admin sessions, admin API keys, and the internal gateway key. Includes: - `tables.py`: list all tables and inspect table schemas - `crud.py`: full CRUD operations (GET, POST, PATCH, DELETE) with soft-delete awareness, born-live inserts, `?include_deleted`, `.../restore`, and `?hard=true` purge - `query.py`: validated read-only SELECT execution via sqlglot parsing, classification, and EXPLAIN dry-run; async query jobs with WebSocket streaming via `DbApiJobService` - `nl.py`: natural-language-to-SQL conversion using the platform AI gateway with re-prompting until validation passes Also register `DbApiJobService` and `PubSubService` in the service manager, add `DBAPI_DIR` to config data paths, and force cleartext `http://` connections to HTTP/1.1 in `curl_transport` to fix large request failures against uvicorn's HTTP/1.1-only internal gateway.
25 lines
799 B
Python
25 lines
799 B
Python
# retoor <retoor@molodetz.nl>
|
|
|
|
|
|
def test_tables_requires_auth(client):
|
|
assert client.get("/dbapi/tables").status_code == 403
|
|
|
|
|
|
def test_tables_lists_and_hides_denied(client, auth):
|
|
response = client.get("/dbapi/tables", headers=auth)
|
|
assert response.status_code == 200
|
|
names = {row["name"] for row in response.json()["tables"]}
|
|
assert "users" in names
|
|
assert "sessions" not in names
|
|
assert "password_resets" not in names
|
|
|
|
|
|
def test_schema(client, auth):
|
|
response = client.get("/dbapi/users/schema", headers=auth)
|
|
assert response.status_code == 200
|
|
assert any(column["name"] == "uid" for column in response.json()["columns"])
|
|
|
|
|
|
def test_schema_denied_table_is_404(client, auth):
|
|
assert client.get("/dbapi/sessions/schema", headers=auth).status_code == 404
|