Beispiel
Keep a tenant scope from being bypassed by an ungrouped Or while inspecting GORM DryRun SQL
sha256:9ff4648d7bd88a17effda2a1b227607fcfea1c19d4ce72eebc4868f0dd20406e
PUBLISHED
L3_CONTRACT_PASS
MIT-0
Fall
- Ziel
- Keep a tenant scope from being bypassed by an ungrouped Or while inspecting GORM DryRun SQL HOW
- Pakete
- gorm.io/gorm v1.31.2 gorm.io/driver/sqlite v1.6.0
- Umgebung
- go 1.26
- Erstellt
- 2026-08-17T01:32:02Z
Häufige Annahme
Calling Scopes(Tenant(id)) before Where(...).Or(...) keeps the tenant predicate in force for both OR branches because the scope appears first in the chain.
So hat der Autor des Samples festgehalten, was eine Entwicklerin oder ein Modell hier erwarten würde. Der Vertrag darunter ist das, was tatsächlich lief.
Contract
- assert Scopes(Tenant(7)).Where("active = ?", true).Or("role = ?", "admin") generates WHERE active = ? OR role = ? AND tenant_id = ?, so SQL precedence allows active rows from other tenants
- assert the ungrouped statement binds [true, "admin", uint(7)] in that order, proving the lazily executed tenant scope is appended after the chained conditions
- assert passing Where("active = ?", true).Or("role = ?", "admin") as one nested Where condition generates WHERE (active = ? OR role = ?) AND tenant_id = ? with the same bind values
- assert DryRun Find executes no SQL against database/sql; only the official SQLite dialector's required select sqlite_version() initialization probe reaches the in-process stub
Dateien
- NOTES.md
- csx.json
- go.mod
- go.sum
- scope.go
- scope_test.go
Verifiziertes Artefakt herunterladen (tar.gz) — genau die Bytes, gegen die der Contract lief
Ursprungs-Seeder
Verifizierungsbelege
- go 1.26 · CONTAINER_RUN · compile:SKIPPED · contract:PASS · load:PASS · resolve:PASS · golang@1 · 2026-08-17 · ed25519:d91480838ac982c9