Skip to content
File

Blob: src/workerd/api/tests/sql-restrict-names-test.js

javascript51 lines
1// Copyright (c) 2025 Cloudflare, Inc.
2// Licensed under the Apache 2.0 license found in the LICENSE file or at:
3// https://opensource.org/licenses/Apache-2.0
4 
5// Tests for the SQL_RESTRICT_RESERVED_NAMES autogate.
6// This test only runs in the @all-autogates variant so it can assert the gated behavior.
7 
8import * as assert from 'node:assert';
9import { DurableObject } from 'cloudflare:workers';
10 
11export class DurableObjectExample extends DurableObject {
12 async fetch(req) {
13 const sql = this.ctx.storage.sql;
14 
15 // Case-insensitive _cf_ prefix blocking: mixed-case variants are rejected.
16 for (const name of ['_CF_test', '_Cf_test', '_cF_test']) {
17 assert.throws(
18 () => sql.exec(`CREATE TABLE ${name} (name TEXT)`),
19 /not authorized/,
20 `Expected CREATE TABLE ${name} to be blocked`
21 );
22 }
23 
24 // Virtual tables with _cf_ prefix are blocked.
25 assert.throws(
26 () => sql.exec('CREATE VIRTUAL TABLE _cf_fts_test USING fts5(content)'),
27 /not authorized/
28 );
29 assert.throws(
30 () => sql.exec('CREATE VIRTUAL TABLE _CF_fts_test USING fts5(content)'),
31 /not authorized/
32 );
33 
34 // Non-_cf_ prefixed virtual tables still work.
35 sql.exec('CREATE VIRTUAL TABLE my_fts USING fts5(content)');
36 sql.exec('DROP TABLE my_fts');
37 
38 return Response.json({ ok: true });
39 }
40}
41 
42export default {
43 async test(ctrl, env, ctx) {
44 let id = env.ns.idFromName('sql-restrict-names');
45 let stub = env.ns.get(id);
46 let response = await stub.fetch('http://x/test');
47 let result = await response.json();
48 assert.ok(result.ok);
49 },
50};