File
Blob: src/workerd/api/tests/sql-restrict-names-test.js
| 1 | // Copyright (c) 2025 Cloudflare, Inc. |
| 2 | // Licensed under the Apache 2.0 license found in the LICENSE file or at: |
| 3 | // https://opensource.org/licenses/Apache-2.0 |
| 4 | |
| 5 | // Tests for the SQL_RESTRICT_RESERVED_NAMES autogate. |
| 6 | // This test only runs in the @all-autogates variant so it can assert the gated behavior. |
| 7 | |
| 8 | import * as assert from 'node:assert'; |
| 9 | import { DurableObject } from 'cloudflare:workers'; |
| 10 | |
| 11 | export class DurableObjectExample extends DurableObject { |
| 12 | async fetch(req) { |
| 13 | const sql = this.ctx.storage.sql; |
| 14 | |
| 15 | // Case-insensitive _cf_ prefix blocking: mixed-case variants are rejected. |
| 16 | for (const name of ['_CF_test', '_Cf_test', '_cF_test']) { |
| 17 | assert.throws( |
| 18 | () => sql.exec(`CREATE TABLE ${name} (name TEXT)`), |
| 19 | /not authorized/, |
| 20 | `Expected CREATE TABLE ${name} to be blocked` |
| 21 | ); |
| 22 | } |
| 23 | |
| 24 | // Virtual tables with _cf_ prefix are blocked. |
| 25 | assert.throws( |
| 26 | () => sql.exec('CREATE VIRTUAL TABLE _cf_fts_test USING fts5(content)'), |
| 27 | /not authorized/ |
| 28 | ); |
| 29 | assert.throws( |
| 30 | () => sql.exec('CREATE VIRTUAL TABLE _CF_fts_test USING fts5(content)'), |
| 31 | /not authorized/ |
| 32 | ); |
| 33 | |
| 34 | // Non-_cf_ prefixed virtual tables still work. |
| 35 | sql.exec('CREATE VIRTUAL TABLE my_fts USING fts5(content)'); |
| 36 | sql.exec('DROP TABLE my_fts'); |
| 37 | |
| 38 | return Response.json({ ok: true }); |
| 39 | } |
| 40 | } |
| 41 | |
| 42 | export default { |
| 43 | async test(ctrl, env, ctx) { |
| 44 | let id = env.ns.idFromName('sql-restrict-names'); |
| 45 | let stub = env.ns.get(id); |
| 46 | let response = await stub.fetch('http://x/test'); |
| 47 | let result = await response.json(); |
| 48 | assert.ok(result.ok); |
| 49 | }, |
| 50 | }; |