End-to-end log pipeline for Linux hosts, per /docs/architecture.md: - proto: shared gRPC contract (agent <-> ingest), Go bindings checked in - agent: Rust, musl-targeted, journald/file sourcing, RFC5424 parser, mTLS gRPC client, no required config for the common case - ingest: Go, single binary with --mode server|consumer|all; gRPC front end forwards to Redpanda unchanged, consumer normalizes and batch-writes to ClickHouse with at-least-once delivery - storage: ClickHouse schema + a plain SQL-file migration runner - api: minimal SELECT-only query endpoint, plain REST (not gRPC+gateway yet -- see api/README.md) - web: SvelteKit static SPA, one query page - transport: Redpanda compose + topic provisioning - cli: sentryctl ping stub - hack/dev-certs: throwaway CA + cert generation for local mTLS - root docker-compose.yml + docs/phase-0-runbook.md tie it together Not yet run end-to-end against real Docker/ClickHouse/Redpanda -- see the runbook's caveats section before relying on this working as-is.
48 lines
1.7 KiB
Go
48 lines
1.7 KiB
Go
package queryapi
|
|
|
|
import (
|
|
"errors"
|
|
"regexp"
|
|
"strings"
|
|
)
|
|
|
|
// disallowedKeyword is defense-in-depth on top of the SELECT-only gate: it
|
|
// catches mutating/administrative statements appearing anywhere in the
|
|
// query (e.g. smuggled into a subquery), not just at the start. This is
|
|
// word-boundary matching, not a real SQL parser.
|
|
var disallowedKeyword = regexp.MustCompile(`(?i)\b(insert|update|delete|alter|drop|truncate|create|grant|revoke|attach|detach|rename|kill|optimize|system|set|exchange|watch)\b`)
|
|
|
|
// validateSelectOnly enforces the Phase 0 query API contract: exactly one
|
|
// SELECT statement and nothing else. This is "basic injection guarding" as
|
|
// specced, not a SQL parser: it will reject some unusual-but-valid SELECTs
|
|
// (e.g. one that references a column literally named "delete") and will
|
|
// not catch every possible abuse (e.g. a syntactically pure SELECT that's
|
|
// simply expensive to run). Both are acceptable for a Phase 0 placeholder
|
|
// that's explicitly superseded by a real query layer in Phase 2 — see
|
|
// /docs/architecture.md.
|
|
func validateSelectOnly(sql string) error {
|
|
trimmed := strings.TrimSpace(sql)
|
|
if trimmed == "" {
|
|
return errors.New("query must not be empty")
|
|
}
|
|
|
|
trimmed = strings.TrimSpace(strings.TrimSuffix(trimmed, ";"))
|
|
if trimmed == "" {
|
|
return errors.New("query must not be empty")
|
|
}
|
|
if strings.Contains(trimmed, ";") {
|
|
return errors.New("only a single statement is allowed")
|
|
}
|
|
|
|
firstWord := strings.ToUpper(strings.Fields(trimmed)[0])
|
|
if firstWord != "SELECT" {
|
|
return errors.New("only SELECT queries are allowed")
|
|
}
|
|
|
|
if disallowedKeyword.MatchString(trimmed) {
|
|
return errors.New("query contains a disallowed keyword")
|
|
}
|
|
|
|
return nil
|
|
}
|