scribe-org / scribe-org/Scribe-Server

Add unit tests for database table name validators

Open Beginner friendly
#80 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

-priority- testing
Dominant language
Go
Stars
12
Forks
14
Avg merge
1d 4h
Merged PRs (30d)
4

Description

Terms
Description

Tests for database.IsValidTableName and IsValidTranslationTableName which are the only guard between user input and fmt.Sprintf("SELECT * FROM %s", ...).

Table names are interpolated, not parameterised, so a regex regression here is a SQL injection. Includes injection payloads, casing and suffix cases.

Contribution

No response

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Locate the definitions of database.IsValidTableName and IsValidTranslationTableName, then inspect the existing Go test layout and run the relevant package tests. Add unit coverage for injection payloads, casing, and suffix cases; done means the validators' accepted and rejected inputs are explicitly tested.

Written by the indexing model from the issue text.

Assessment

Tech stack
go
Domain
databases, security, testing-qa
Issue type
Refactor
Difficulty
2/5
Estimated time
1-3 hours
Activity status
Active
Clarity
Mostly clear
Newbie friendliness
78/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.