Skip to content

Document that SQLToolset does not check functions without allowed_tables - #74444

Merged
kaxil merged 2 commits into
apache:mainfrom
astronomer:common-ai-deps-and-security-docs
Oct 10, 2026
Merged

kaxil merged 2 commits into
apache:mainfrom
astronomer:common-ai-deps-and-security-docs

Conversation

@Lee-W

@Lee-W Lee-W commented Oct 8, 2026

Copy link
Copy Markdown
Member

Why

SQLToolset rejects write statements by scanning the parsed statement, but without allowed_tables it does not examine function calls inside a SELECT. The docs missed it. A SELECT can therefore still call side-effecting functions such as nextval, pg_terminate_backend or dblink_exec. These pass validation and run with the connection's privileges.

What

  • providers/common/ai/docs/toolsets/sql.rst: add a paragraph that says the check inspects statement types, not what a function does. It also says that without allowed_tables a function call inside a SELECT is not examined. Setting allowed_tables turns on the function check: every function sqlglot cannot type is rejected unless it is listed in allowed_functions. Either way, it recommends a least-privilege role, and a read-only transaction or session where the database supports one.
  • providers/common/ai/docs/agent_security.rst: in the SQLToolset read-only row of the layers table, add the same limitation and the same recommendation.

Was generative AI tooling used to co-author this PR?
  • Yes (please specify the tool below)

Generated-by: [Claude] following the guidelines


  • Read the Pull Request Guidelines for more information. Note: commit author/co-author name and email in commits become permanently public when merged.
  • For fundamental code changes, an Airflow Improvement Proposal (AIP) is needed.
  • When adding dependency, check compliance with the ASF 3rd Party License Policy.
  • For significant user-facing changes create newsfragment: {pr_number}.significant.rst, in airflow-core/newsfragments. You can add this file in a follow-up commit after the PR is created so you know the PR number.

Comment thread providers/common/ai/docs/agent_security.rst Outdated
Comment thread providers/common/ai/docs/agent_security.rst
Lee-W added 2 commits October 9, 2026 05:53
Without allowed_tables, a SELECT can still call side-effecting functions such as nextval or pg_terminate_backend. Recommend a least-privilege role.
- Recommend a least-privilege role together with a read-only role/session
  default, and note that a transaction cannot be set from the Dag.
- State that the allowed_tables function check rejects only functions
  sqlglot cannot type, so typed syntax such as T-SQL NEXT VALUE FOR or
  Snowflake seq.nextval still passes.
@Lee-W
Lee-W force-pushed the common-ai-deps-and-security-docs branch from 502f952 to 938b642 Compare October 9, 2026 04:53
@kaxil
kaxil merged commit 0bae39f into apache:main Oct 10, 2026
71 checks passed
@kaxil
kaxil deleted the common-ai-deps-and-security-docs branch October 10, 2026 12:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants