Treat a malformed data source id as ErrNotFound, not a raw pg error
SetDataSourceClickHouseCredentials let a non-UUID id leak Postgres's raw 22P02 (invalid_text_representation) error past the store's ErrNotFound boundary. A malformed id can never match a row either way, so it should be treated the same as "no such row" rather than exposing a database-internal error past this package's boundary. Found via a live Postgres integration test.
This commit is contained in:
@@ -27,6 +27,7 @@ import (
|
|||||||
|
|
||||||
"github.com/google/uuid"
|
"github.com/google/uuid"
|
||||||
"github.com/jackc/pgx/v5"
|
"github.com/jackc/pgx/v5"
|
||||||
|
"github.com/jackc/pgx/v5/pgconn"
|
||||||
"github.com/jackc/pgx/v5/pgxpool"
|
"github.com/jackc/pgx/v5/pgxpool"
|
||||||
)
|
)
|
||||||
|
|
||||||
@@ -534,6 +535,13 @@ func (s *Store) SetDataSourceClickHouseCredentials(ctx context.Context, id, user
|
|||||||
`UPDATE data_sources SET clickhouse_username = $2, clickhouse_password = $3 WHERE id = $1`,
|
`UPDATE data_sources SET clickhouse_username = $2, clickhouse_password = $3 WHERE id = $1`,
|
||||||
id, username, password)
|
id, username, password)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
|
// A malformed id (not valid UUID syntax) can never match a row
|
||||||
|
// either way -- treat it the same as "no such row" rather than
|
||||||
|
// leaking Postgres's raw 22P02 error past this store's boundary.
|
||||||
|
var pgErr *pgconn.PgError
|
||||||
|
if errors.As(err, &pgErr) && pgErr.Code == "22P02" {
|
||||||
|
return ErrNotFound
|
||||||
|
}
|
||||||
return fmt.Errorf("rbacstore: setting data source credentials: %w", err)
|
return fmt.Errorf("rbacstore: setting data source credentials: %w", err)
|
||||||
}
|
}
|
||||||
if tag.RowsAffected() == 0 {
|
if tag.RowsAffected() == 0 {
|
||||||
|
|||||||
Reference in New Issue
Block a user