Skip to content

fix(jdbc): use trusted configured driver download URLs - #39

Open
HandSonic wants to merge 104 commits into
mainfrom
fix/hsqldb-driver-download
Open

HandSonic wants to merge 104 commits into
mainfrom
fix/hsqldb-driver-download

Conversation

@HandSonic

@HandSonic HandSonic commented Aug 12, 2026 •

Copy link
Copy Markdown
Owner

Summary

  • Resolve missing JDBC driver jars from server-owned plugin downloadJdbcDriverUrls, so HSQLDB uses its configured Maven Central artifact instead of the unavailable legacy CDN path.
  • Match trusted metadata by authoritative database type plus exact driver jar and class. Request-supplied DriverConfig.downloadJdbcDriverUrls are never selected for automatic downloads.
  • Propagate the parent database type into built-in driver configs and preserve the legacy JdbcDriverManager public APIs.
  • Resolve the JDBC driver directory from the active user.home and create it consistently for downloads, copied drivers, and multipart uploads.

Security

Automatic downloads only use URLs from the server-owned plugin registry. A request can choose an existing driver declaration, but cannot override its download URL or introduce an outbound destination. Custom uploaded drivers continue to load from local files.

Tests

  • HsqldbTrustedDriverDownloadTest: trusted HSQLDB selection, malicious request URL rejection, and legacy getClassLoader / getProperty / getConnection coverage.
  • JdbcJarUtilsTest: 7 passed.
  • Driver copy and multipart upload directory regressions: 1 passed each.
  • Full tools/domain-api/SPI relevant tests passed.
  • SPI dependency reactor package: 6/6 modules passed.
  • Domain-core/web dependency reactor package: 8/8 modules passed.
  • git diff --check passed.

Latest-main verification (2026-09-04)

  • Rebased onto 144a04ee2; a targeted 48-module reactor compiled every backend plugin and passed all five JDBC/HSQL/config flow tests, including the Spring Boot API flow.n- Full 15-module affected/dependent reactor passed, including tools (71), web (80), and generic (50; 13 environment skips).n- Combined with fix(tools): harden asynchronous JDBC downloads OtterMind/Chat2DB#2687 using a semantic conflict resolution; full combined tools suite passed (76 tests), preserving dynamic runtime paths, atomic publication, and daemon workers.

@HandSonic
HandSonic force-pushed the fix/hsqldb-driver-download branch from cf555e1 to 70b9278 Compare August 12, 2026 04:43
@HandSonic
HandSonic force-pushed the fix/hsqldb-driver-download branch from 70b9278 to fffa3e0 Compare August 19, 2026 20:16
Aias00 and others added 26 commits August 21, 2026 02:36
Add `visible` field to TableIndex domain model, read the `Visible` column
from SHOW INDEXES in MySQL metadata, generate INVISIBLE keyword in index
DDL, and add buildAlterIndexVisibility for ALTER INDEX syntax.

Frontend: add a "Visible" column to the index editor with a
VISIBLE/INVISIBLE toggle, disabled for primary keys, gated to MySQL only.

Test fixtures: init.sql, grants.sql, cleanup.sql, README.md under
script/test-fixtures/mysql/MYSQL-OBJ-006/.

Closes OtterMind#2574
Replace hardcoded INVISIBLE, ALTER INDEX strings with constants
SQL_INVISIBLE and SQL_ALTER_INDEX from MysqlSqlConstants.
…ABLE

buildAlterIndexVisibility was dead code: a visibility-only change fell
through to DROP+ADD, rebuilding the whole index. ALTER TABLE now emits
ALTER INDEX ... VISIBLE/INVISIBLE when the modified index differs from
the stored one only in visibility (and is not the primary key), and
falls back to the rebuild path otherwise.
Add `visible` field to TableColumn domain model, detect "INVISIBLE"
from the EXTRA column in information_schema, and generate the INVISIBLE
keyword in column DDL via MysqlColumnTypeEnum.

Frontend: add a "Visible" column to the column editor with a
VISIBLE/INVISIBLE toggle, gated to MySQL only.

Test fixtures: init.sql, grants.sql, cleanup.sql, README.md under
script/test-fixtures/mysql/MYSQL-OBJ-003/.

Closes OtterMind#2571
Replace hardcoded INVISIBLE string with SQL_INVISIBLE constant
from MysqlMetaDataConstants in MysqlColumnTypeEnum.
MySQL column grammar requires VISIBLE/INVISIBLE before the COMMENT
clause; the previous order produced ERROR 1064 for invisible columns
that carry a comment.
Adds a read-only Active Transactions view for the datasource node:
- Lists innodb_trx joined with processlist: transaction ID, state,
  start time, age, isolation level, rows locked/modified, thread ID,
  user, host, database, and current SQL.
- Works on MySQL 5.7 and 8.0; SQL text is null without PROCESS and
  surfaced as an explicit unavailable state instead of a blank value.
- New tree menu entry with a refreshable table dialog, i18n in all five
  locales, and MYSQL-OPS-002 fixtures (admin vs limited accounts).
…tolerant fallback

1. Add `resolveShellCandidates` method to return available shell candidates based on the operating system
2. Modify `create` method to sequentially try starting shells from the candidate list, automatically falling back to the next on failure
3. Add unit tests to verify shell candidate resolution and exception scenarios
4. Add compatibility handling for scenarios where enterprise security software blocks the default shell
…igurable default shell and improved shell candidate resolution

- Introduce DEFAULT_SHELL_PROPERTY configuration property for setting the default shell
- Add processFactory factory method to support custom process creation logic
- Refactor create method to accept pre-resolved shell candidate list
- Extract PtyProcess startup logic into a separate startProcess method
- Add proper argument configuration for PowerShell and CMD commands (-NoLogo, -NoExit, -Command, etc.)
- Improve shell candidate resolution order on Windows (pwsh → PowerShell → cmd)
- Add support for zsh and bash colored prompts
- Add test helper methods to reset factory and event publisher state
- Add comprehensive unit tests covering shell configuration and failover scenarios
- Change inner classes and enums to public to support external access
- Add command parser interface to support custom command lookup logic
- route DM SQL through the DM command executor
- add dedicated DM lexer and parser support
- retrieve execution plans through DmdbConnection.getExplainInfo
- preserve SQL type, metrics, streaming, and error behavior
- cover explicit EXPLAIN, Explain actions, cancellation, and driver isolation

Fixes OtterMind#2762
openai0229 and others added 29 commits September 2, 2026 13:46
…pace-storage-quota

fix(workspace): keep local files out of localStorage
…erformance

perf(mysql): avoid full parse for ordinary completion scripts
refactor(terminal): refactor terminal shell startup logic with fault-tolerant fallback
…-column-2571

feat(mysql): invisible column management for MySQL 8.0.23+
…edit-actions

fix(result): stabilize sorting and edit actions
…active-transaction-2595

# Conflicts:
#	chat2db-community-client/package.json
…-theme-accent

fix(workspace): smooth panel resizing and restore theme accents
…ansaction-2595

feat(mysql): active InnoDB transaction inspection (OtterMind#2595)
…-expiration

fix(redis): persist no-expiration TTL updates
# Conflicts:
#	chat2db-community-client/package.json
#	chat2db-community-client/src/pages/main/workspace/components/WorkspaceExtend/GlobalExtendComponents/accountGrantsRequest.test.ts
#	chat2db-community-client/src/pages/main/workspace/components/WorkspaceExtend/GlobalExtendComponents/accountGrantsRequest.ts
…atest-request

fix(frontend): ignore stale account grants
@HandSonic
HandSonic force-pushed the fix/hsqldb-driver-download branch from fffa3e0 to bebbf8c Compare September 3, 2026 23:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants