fix: Update the lint query with the latest from splinter repo (#22672)

* Update the lint query with the latest from splinter repo.

* Update the lint to exclude some extension schemas.
This commit is contained in:
Ivan Vasilov authored and GitHub committed 2024-04-12 17:56:22 +02:00
1 parent 9cc8fec8f7
commit 5458fa4f32
1 file changed
+10 -10
+10 -10
View File
@@ -61,7 +61,7 @@ from
where
idx.index_ is null
and fk.schema_::text not in (
'pg_catalog', 'information_schema', 'auth', 'extensions', 'graphql', 'graphql_public', 'net', 'pgsodium', 'storage', 'supabase_functions', 'vault'
'_timescaledb_internal', 'auth', 'cron', 'extensions', 'graphql', 'graphql_public', 'information_schema', 'net', 'pg_catalog', 'pgbouncer', 'pgroonga', 'pgsodium', 'pgsodium_masks', 'pgtle', 'realtime', 'repack', 'storage', 'supabase_functions', 'supabase_migrations', 'tiger', 'topology', 'vault'
)
order by
fk.table_,
@@ -230,7 +230,7 @@ from
where
is_rls_active
and schema_::text not in (
'pg_catalog', 'information_schema', 'auth', 'extensions', 'graphql', 'graphql_public', 'net', 'pgsodium', 'storage', 'supabase_functions', 'vault'
'_timescaledb_internal', 'auth', 'cron', 'extensions', 'graphql', 'graphql_public', 'information_schema', 'net', 'pg_catalog', 'pgbouncer', 'pgroonga', 'pgsodium', 'pgsodium_masks', 'pgtle', 'realtime', 'repack', 'storage', 'supabase_functions', 'supabase_migrations', 'tiger', 'topology', 'vault'
)
and (
(
@@ -279,7 +279,7 @@ from
where
pgc.relkind = 'r' -- regular tables
and pgns.nspname not in (
'pg_catalog', 'information_schema', 'auth', 'extensions', 'graphql', 'graphql_public', 'net', 'pgsodium', 'storage', 'supabase_functions', 'vault'
'_timescaledb_internal', 'auth', 'cron', 'extensions', 'graphql', 'graphql_public', 'information_schema', 'net', 'pg_catalog', 'pgbouncer', 'pgroonga', 'pgsodium', 'pgsodium_masks', 'pgtle', 'realtime', 'repack', 'storage', 'supabase_functions', 'supabase_migrations', 'tiger', 'topology', 'vault'
)
group by
pgc.oid,
@@ -322,7 +322,7 @@ where
and not pi.indisunique
and not pi.indisprimary
and psui.schemaname not in (
'pg_catalog', 'information_schema', 'auth', 'net', 'pgsodium', 'storage', 'supabase_functions', 'vault'
'_timescaledb_internal', 'auth', 'cron', 'extensions', 'graphql', 'graphql_public', 'information_schema', 'net', 'pg_catalog', 'pgbouncer', 'pgroonga', 'pgsodium', 'pgsodium_masks', 'pgtle', 'realtime', 'repack', 'storage', 'supabase_functions', 'supabase_migrations', 'tiger', 'topology', 'vault'
))
union all
(
@@ -376,7 +376,7 @@ from
where
c.relkind = 'r' -- regular tables
and n.nspname not in (
'pg_catalog', 'information_schema', 'auth', 'extensions', 'graphql', 'graphql_public', 'net', 'pgsodium', 'storage', 'supabase_functions', 'vault'
'_timescaledb_internal', 'auth', 'cron', 'extensions', 'graphql', 'graphql_public', 'information_schema', 'net', 'pg_catalog', 'pgbouncer', 'pgroonga', 'pgsodium', 'pgsodium_masks', 'pgtle', 'realtime', 'repack', 'storage', 'supabase_functions', 'supabase_migrations', 'tiger', 'topology', 'vault'
)
and r.rolname not like 'pg_%'
and r.rolname not like 'supabase%admin'
@@ -421,7 +421,7 @@ from
where
c.relkind = 'r' -- regular tables
and n.nspname not in (
'pg_catalog', 'information_schema', 'auth', 'extensions', 'graphql', 'graphql_public', 'net', 'pgsodium', 'storage', 'supabase_functions', 'vault'
'_timescaledb_internal', 'auth', 'cron', 'extensions', 'graphql', 'graphql_public', 'information_schema', 'net', 'pg_catalog', 'pgbouncer', 'pgroonga', 'pgsodium', 'pgsodium_masks', 'pgtle', 'realtime', 'repack', 'storage', 'supabase_functions', 'supabase_migrations', 'tiger', 'topology', 'vault'
)
-- RLS is disabled
and not c.relrowsecurity
@@ -460,7 +460,7 @@ from
where
c.relkind = 'r' -- regular tables
and n.nspname not in (
'pg_catalog', 'information_schema', 'auth', 'extensions', 'graphql', 'graphql_public', 'net', 'pgsodium', 'storage', 'supabase_functions', 'vault'
'_timescaledb_internal', 'auth', 'cron', 'extensions', 'graphql', 'graphql_public', 'information_schema', 'net', 'pg_catalog', 'pgbouncer', 'pgroonga', 'pgsodium', 'pgsodium_masks', 'pgtle', 'realtime', 'repack', 'storage', 'supabase_functions', 'supabase_migrations', 'tiger', 'topology', 'vault'
)
-- RLS is enabled
and c.relrowsecurity
@@ -508,7 +508,7 @@ from
where
c.relkind in ('r', 'm') -- tables and materialized views
and n.nspname not in (
'pg_catalog', 'information_schema', 'auth', 'extensions', 'graphql', 'graphql_public', 'net', 'pgsodium', 'storage', 'supabase_functions', 'vault'
'_timescaledb_internal', 'auth', 'cron', 'extensions', 'graphql', 'graphql_public', 'information_schema', 'net', 'pg_catalog', 'pgbouncer', 'pgroonga', 'pgsodium', 'pgsodium_masks', 'pgtle', 'realtime', 'repack', 'storage', 'supabase_functions', 'supabase_migrations', 'tiger', 'topology', 'vault'
)
group by
n.nspname,
@@ -562,7 +562,7 @@ select
'function_search_path_mutable' as name,
'WARN' as level,
'EXTERNAL' as facing,
'Detects functions with a mutable search_path parameter which could fail to execute successfully for some roles.' as description,
'Detects functions with a mutable search_path parameter which could fail to execute sucessfully for some roles.' as description,
format(
'Function \`%s.%s\` has a role mutable search_path',
n.nspname,
@@ -586,7 +586,7 @@ from
on p.pronamespace = n.oid
where
n.nspname not in (
'pg_catalog', 'information_schema', 'auth', 'extensions', 'graphql', 'graphql_public', 'net', 'pgsodium', 'storage', 'supabase_functions', 'vault'
'_timescaledb_internal', 'auth', 'cron', 'extensions', 'graphql', 'graphql_public', 'information_schema', 'net', 'pg_catalog', 'pgbouncer', 'pgroonga', 'pgsodium', 'pgsodium_masks', 'pgtle', 'realtime', 'repack', 'storage', 'supabase_functions', 'supabase_migrations', 'tiger', 'topology', 'vault'
)
-- Search path not set to ''
and not coalesce(p.proconfig, '{}') && array['search_path=""'])