Ir al contenido

doctor, diff y rehearse

Rómpela aquí. No en producción.

Ventana de terminal
kling db tenant-check crm-1

Salida

kling db tenant-check: crm-1 (database appdb, role app, column tenant_id, setting app.tenant_id)
tenants tested: 3 (-max 5)
FAIL public.accounts (RLS on, 1 policy)
fail no tenant (setting unset): SELECT sees 4 row(s) with no tenant set
fail no tenant (setting unset): INSERT of a row for another tenant passed row level security; only a constraint stopped it (23505)
fail no tenant (setting unset): UPDATE moving a row to another tenant succeeded (1 row(s), rolled back)
fail no tenant (setting unset): UPDATE of rows with no tenant set succeeded (4 row(s), rolled back)
why: policy "tenant_isolation" (permissive, ALL): fail-open in USING: <tenant setting> IS NULL is true when the setting is missing, so with no tenant set every row passes
fix: make the policy fail closed: current_setting('<var>') without missing_ok (errors when unset), or compare only tenant_id = current_setting(...) with no IS NULL / '' / COALESCE escape
PASS public.contacts (RLS on, 1 policy)
summary: 2 table(s), 1 not passing; 4 failed check(s), 0 error(s), 2 skipped

Sale con 1 si hay fugas. Las escrituras se deshacen siempre.

Ventana de terminal
kling db doctor t1 # reglas DB001-DB055
kling db doctor -url 'postgres://…' # un Postgres que ya tienes, por TLS verificado
Ventana de terminal
kling db diff t1 t2

Esquema, funciones, grants y filas nuevas, borradas o cambiadas por clave primaria. Al host solo llegan huellas con sal: ni un valor sale de la base.

Ventana de terminal
kling db rehearse pg -migrations migrations/

Aplica cada .sql en una copia desechable, como el rol de la aplicación, y mide tiempo, tamaño y locks fuertes. Si un fichero falla, sale con 1.

Ventana de terminal
kling db snapshot t1 antes
kling db undo t1 antes