fix(tool/bigquery): prevent allowedDatasets bypass in forecast query#3324
Conversation
There was a problem hiding this comment.
Code Review
This pull request updates the BigQuery analyze contribution and forecast tools to use string parameters with single-quote escaping, and moves dataset validation to a dry-run query on the final generated SQL. The reviewer identified a critical SQL injection vulnerability caused by using strings.Trim to strip single quotes, which can bypass the single-quote check. To address this and other potential bugs, the reviewer recommended safely stripping exactly one leading and trailing single quote instead of using strings.Trim. Additionally, the reviewer flagged potential nil pointer dereferences when accessing dryRunJob.Statistics.Query without first checking if dryRunJob.Statistics is nil.
aec5d3b to
cd77a99
Compare
|
/gemini review |
There was a problem hiding this comment.
Code Review
This pull request updates the BigQuery analyze contribution and forecast tools to support single-quote escaping for string parameters and improves dataset validation by dry-running the fully assembled SQL queries instead of just the raw input queries. The review feedback suggests refactoring the code to extract a shared helper function for stripping single quotes, avoiding duplicate SQL query construction, and adding defensive nil checks on the dry-run job results to prevent potential nil pointer dereferences.
fdfc9d4 to
5370cbd
Compare
averikitsch
left a comment
There was a problem hiding this comment.
Can we get a test to ensure no regressions? Thanks!
67bbf6e to
de06310
Compare
allowedDatasets bypass in forecast query
…escaped inner errors
|
🧨 Preview deployments removed. Cloudflare Pages environments for |
🤖 I have created a release *beep* *boop* --- ## [1.4.0](v1.3.0...v1.4.0) (2026-06-04) ### Features * **ci:** Add support for windows/arm64 binary distribution ([#3231](#3231)) ([10abf3b](10abf3b)) * **datalineage:** Add Data Lineage integration ([#3285](#3285)) ([19353c3](19353c3)) * **server:** Ignore unknown tools at startup with `--ignore-unknown-tools` flag ([#3353](#3353)) ([5f0304f](5f0304f)) * **tools/cloudsqlpg:** Add remaining vector assist tools for Cloud SQL Postgres ([#3203](#3203)) ([b514cbd](b514cbd)) * **tools/spanner-search-catalog:** Implement search_catalog tool ([#3140](#3140)) ([defc086](defc086)) ### Bug Fixes * **auth/generic:** Enforce issuer presence in opaque token validation ([#3360](#3360)) ([1d8df0d](1d8df0d)) * **auth:** Separate Google and Generic MCP OAuth verification ([#3341](#3341)) ([dfd66ee](dfd66ee)) * **mcp:** Support annotations and metadata within Tools to earlier MCP schemas ([#3300](#3300)) ([9a88c72](9a88c72)) * **oracle:** Remove trailing semicolons from prebuilt tools ([#3215](#3215)) ([fcad02d](fcad02d)) * **server/auth:** Centralize tool scopes validation ([#3335](#3335)) ([adce4ab](adce4ab)) * **server:** Return null id for batch request rejection ([#3333](#3333)) ([0b18d58](0b18d58)) * **source/dataplex:** Limit search results to pageSize ([#3323](#3323)) ([905c1f6](905c1f6)), closes [#3308](#3308) * **telemetry:** Allow GCP project override ([#2960](#2960)) ([3c83ba5](3c83ba5)) * **tool/bigquery:** Prevent `allowedDatasets` bypass in forecast query ([#3324](#3324)) ([45df461](45df461)) * **tool/clickhouse:** Handle ignored ProcessParameters error ([#3340](#3340)) ([ddfd887](ddfd887)) * **tools/clickhouse,tools/bigquery:** Validate identifier parameters to prevent injection ([#3219](#3219)) ([2f45f75](2f45f75)) * **tools/looker:** Escape filter values for unquoted parameters ([#3289](#3289)) ([1711156](1711156)) --- This PR was generated with [Release Please](https://github.com/googleapis/release-please). See [documentation](https://github.com/googleapis/release-please#release-please). --------- Co-authored-by: release-please[bot] <55107282+release-please[bot]@users.noreply.github.com> Co-authored-by: Yuan Teoh <45984206+Yuan325@users.noreply.github.com>
🤖 I have created a release *beep* *boop* --- ## [1.4.0](v1.3.0...v1.4.0) (2026-06-04) ### Features * **ci:** Add support for windows/arm64 binary distribution ([#3231](#3231)) ([10abf3b](10abf3b)) * **datalineage:** Add Data Lineage integration ([#3285](#3285)) ([19353c3](19353c3)) * **server:** Ignore unknown tools at startup with `--ignore-unknown-tools` flag ([#3353](#3353)) ([5f0304f](5f0304f)) * **tools/cloudsqlpg:** Add remaining vector assist tools for Cloud SQL Postgres ([#3203](#3203)) ([b514cbd](b514cbd)) * **tools/spanner-search-catalog:** Implement search_catalog tool ([#3140](#3140)) ([defc086](defc086)) ### Bug Fixes * **auth/generic:** Enforce issuer presence in opaque token validation ([#3360](#3360)) ([1d8df0d](1d8df0d)) * **auth:** Separate Google and Generic MCP OAuth verification ([#3341](#3341)) ([dfd66ee](dfd66ee)) * **mcp:** Support annotations and metadata within Tools to earlier MCP schemas ([#3300](#3300)) ([9a88c72](9a88c72)) * **oracle:** Remove trailing semicolons from prebuilt tools ([#3215](#3215)) ([fcad02d](fcad02d)) * **server/auth:** Centralize tool scopes validation ([#3335](#3335)) ([adce4ab](adce4ab)) * **server:** Return null id for batch request rejection ([#3333](#3333)) ([0b18d58](0b18d58)) * **source/dataplex:** Limit search results to pageSize ([#3323](#3323)) ([905c1f6](905c1f6)), closes [#3308](#3308) * **telemetry:** Allow GCP project override ([#2960](#2960)) ([3c83ba5](3c83ba5)) * **tool/bigquery:** Prevent `allowedDatasets` bypass in forecast query ([#3324](#3324)) ([45df461](45df461)) * **tool/clickhouse:** Handle ignored ProcessParameters error ([#3340](#3340)) ([ddfd887](ddfd887)) * **tools/clickhouse,tools/bigquery:** Validate identifier parameters to prevent injection ([#3219](#3219)) ([2f45f75](2f45f75)) * **tools/looker:** Escape filter values for unquoted parameters ([#3289](#3289)) ([1711156](1711156)) --- This PR was generated with [Release Please](https://github.com/googleapis/release-please). See [documentation](https://github.com/googleapis/release-please#release-please). --------- Co-authored-by: release-please[bot] <55107282+release-please[bot]@users.noreply.github.com> Co-authored-by: Yuan Teoh <45984206+Yuan325@users.noreply.github.com> d67cfbe
🤖 I have created a release *beep* *boop* --- ## [1.4.0](googleapis/mcp-toolbox@v1.3.0...v1.4.0) (2026-06-04) ### Features * **ci:** Add support for windows/arm64 binary distribution ([googleapis#3231](googleapis#3231)) ([10abf3b](googleapis@10abf3b)) * **datalineage:** Add Data Lineage integration ([googleapis#3285](googleapis#3285)) ([19353c3](googleapis@19353c3)) * **server:** Ignore unknown tools at startup with `--ignore-unknown-tools` flag ([googleapis#3353](googleapis#3353)) ([5f0304f](googleapis@5f0304f)) * **tools/cloudsqlpg:** Add remaining vector assist tools for Cloud SQL Postgres ([googleapis#3203](googleapis#3203)) ([b514cbd](googleapis@b514cbd)) * **tools/spanner-search-catalog:** Implement search_catalog tool ([googleapis#3140](googleapis#3140)) ([defc086](googleapis@defc086)) ### Bug Fixes * **auth/generic:** Enforce issuer presence in opaque token validation ([googleapis#3360](googleapis#3360)) ([1d8df0d](googleapis@1d8df0d)) * **auth:** Separate Google and Generic MCP OAuth verification ([googleapis#3341](googleapis#3341)) ([dfd66ee](googleapis@dfd66ee)) * **mcp:** Support annotations and metadata within Tools to earlier MCP schemas ([googleapis#3300](googleapis#3300)) ([9a88c72](googleapis@9a88c72)) * **oracle:** Remove trailing semicolons from prebuilt tools ([googleapis#3215](googleapis#3215)) ([fcad02d](googleapis@fcad02d)) * **server/auth:** Centralize tool scopes validation ([googleapis#3335](googleapis#3335)) ([adce4ab](googleapis@adce4ab)) * **server:** Return null id for batch request rejection ([googleapis#3333](googleapis#3333)) ([0b18d58](googleapis@0b18d58)) * **source/dataplex:** Limit search results to pageSize ([googleapis#3323](googleapis#3323)) ([905c1f6](googleapis@905c1f6)), closes [googleapis#3308](googleapis#3308) * **telemetry:** Allow GCP project override ([googleapis#2960](googleapis#2960)) ([3c83ba5](googleapis@3c83ba5)) * **tool/bigquery:** Prevent `allowedDatasets` bypass in forecast query ([googleapis#3324](googleapis#3324)) ([45df461](googleapis@45df461)) * **tool/clickhouse:** Handle ignored ProcessParameters error ([googleapis#3340](googleapis#3340)) ([ddfd887](googleapis@ddfd887)) * **tools/clickhouse,tools/bigquery:** Validate identifier parameters to prevent injection ([googleapis#3219](googleapis#3219)) ([2f45f75](googleapis@2f45f75)) * **tools/looker:** Escape filter values for unquoted parameters ([googleapis#3289](googleapis#3289)) ([1711156](googleapis@1711156)) --- This PR was generated with [Release Please](https://github.com/googleapis/release-please). See [documentation](https://github.com/googleapis/release-please#release-please). --------- Co-authored-by: release-please[bot] <55107282+release-please[bot]@users.noreply.github.com> Co-authored-by: Yuan Teoh <45984206+Yuan325@users.noreply.github.com> d67cfbe
🤖 I have created a release *beep* *boop* --- ## [1.4.0](googleapis/mcp-toolbox@v1.3.0...v1.4.0) (2026-06-04) ### Features * **ci:** Add support for windows/arm64 binary distribution ([googleapis#3231](googleapis#3231)) ([10abf3b](googleapis@10abf3b)) * **datalineage:** Add Data Lineage integration ([googleapis#3285](googleapis#3285)) ([19353c3](googleapis@19353c3)) * **server:** Ignore unknown tools at startup with `--ignore-unknown-tools` flag ([googleapis#3353](googleapis#3353)) ([5f0304f](googleapis@5f0304f)) * **tools/cloudsqlpg:** Add remaining vector assist tools for Cloud SQL Postgres ([googleapis#3203](googleapis#3203)) ([b514cbd](googleapis@b514cbd)) * **tools/spanner-search-catalog:** Implement search_catalog tool ([googleapis#3140](googleapis#3140)) ([defc086](googleapis@defc086)) ### Bug Fixes * **auth/generic:** Enforce issuer presence in opaque token validation ([googleapis#3360](googleapis#3360)) ([1d8df0d](googleapis@1d8df0d)) * **auth:** Separate Google and Generic MCP OAuth verification ([googleapis#3341](googleapis#3341)) ([dfd66ee](googleapis@dfd66ee)) * **mcp:** Support annotations and metadata within Tools to earlier MCP schemas ([googleapis#3300](googleapis#3300)) ([9a88c72](googleapis@9a88c72)) * **oracle:** Remove trailing semicolons from prebuilt tools ([googleapis#3215](googleapis#3215)) ([fcad02d](googleapis@fcad02d)) * **server/auth:** Centralize tool scopes validation ([googleapis#3335](googleapis#3335)) ([adce4ab](googleapis@adce4ab)) * **server:** Return null id for batch request rejection ([googleapis#3333](googleapis#3333)) ([0b18d58](googleapis@0b18d58)) * **source/dataplex:** Limit search results to pageSize ([googleapis#3323](googleapis#3323)) ([905c1f6](googleapis@905c1f6)), closes [googleapis#3308](googleapis#3308) * **telemetry:** Allow GCP project override ([googleapis#2960](googleapis#2960)) ([3c83ba5](googleapis@3c83ba5)) * **tool/bigquery:** Prevent `allowedDatasets` bypass in forecast query ([googleapis#3324](googleapis#3324)) ([45df461](googleapis@45df461)) * **tool/clickhouse:** Handle ignored ProcessParameters error ([googleapis#3340](googleapis#3340)) ([ddfd887](googleapis@ddfd887)) * **tools/clickhouse,tools/bigquery:** Validate identifier parameters to prevent injection ([googleapis#3219](googleapis#3219)) ([2f45f75](googleapis@2f45f75)) * **tools/looker:** Escape filter values for unquoted parameters ([googleapis#3289](googleapis#3289)) ([1711156](googleapis@1711156)) --- This PR was generated with [Release Please](https://github.com/googleapis/release-please). See [documentation](https://github.com/googleapis/release-please#release-please). --------- Co-authored-by: release-please[bot] <55107282+release-please[bot]@users.noreply.github.com> Co-authored-by: Yuan Teoh <45984206+Yuan325@users.noreply.github.com> d67cfbe
🤖 I have created a release *beep* *boop* --- ## [1.4.0](googleapis/mcp-toolbox@v1.3.0...v1.4.0) (2026-06-04) ### Features * **ci:** Add support for windows/arm64 binary distribution ([googleapis#3231](googleapis#3231)) ([10abf3b](googleapis@10abf3b)) * **datalineage:** Add Data Lineage integration ([googleapis#3285](googleapis#3285)) ([19353c3](googleapis@19353c3)) * **server:** Ignore unknown tools at startup with `--ignore-unknown-tools` flag ([googleapis#3353](googleapis#3353)) ([5f0304f](googleapis@5f0304f)) * **tools/cloudsqlpg:** Add remaining vector assist tools for Cloud SQL Postgres ([googleapis#3203](googleapis#3203)) ([b514cbd](googleapis@b514cbd)) * **tools/spanner-search-catalog:** Implement search_catalog tool ([googleapis#3140](googleapis#3140)) ([defc086](googleapis@defc086)) ### Bug Fixes * **auth/generic:** Enforce issuer presence in opaque token validation ([googleapis#3360](googleapis#3360)) ([1d8df0d](googleapis@1d8df0d)) * **auth:** Separate Google and Generic MCP OAuth verification ([googleapis#3341](googleapis#3341)) ([dfd66ee](googleapis@dfd66ee)) * **mcp:** Support annotations and metadata within Tools to earlier MCP schemas ([googleapis#3300](googleapis#3300)) ([9a88c72](googleapis@9a88c72)) * **oracle:** Remove trailing semicolons from prebuilt tools ([googleapis#3215](googleapis#3215)) ([fcad02d](googleapis@fcad02d)) * **server/auth:** Centralize tool scopes validation ([googleapis#3335](googleapis#3335)) ([adce4ab](googleapis@adce4ab)) * **server:** Return null id for batch request rejection ([googleapis#3333](googleapis#3333)) ([0b18d58](googleapis@0b18d58)) * **source/dataplex:** Limit search results to pageSize ([googleapis#3323](googleapis#3323)) ([905c1f6](googleapis@905c1f6)), closes [googleapis#3308](googleapis#3308) * **telemetry:** Allow GCP project override ([googleapis#2960](googleapis#2960)) ([3c83ba5](googleapis@3c83ba5)) * **tool/bigquery:** Prevent `allowedDatasets` bypass in forecast query ([googleapis#3324](googleapis#3324)) ([45df461](googleapis@45df461)) * **tool/clickhouse:** Handle ignored ProcessParameters error ([googleapis#3340](googleapis#3340)) ([ddfd887](googleapis@ddfd887)) * **tools/clickhouse,tools/bigquery:** Validate identifier parameters to prevent injection ([googleapis#3219](googleapis#3219)) ([2f45f75](googleapis@2f45f75)) * **tools/looker:** Escape filter values for unquoted parameters ([googleapis#3289](googleapis#3289)) ([1711156](googleapis@1711156)) --- This PR was generated with [Release Please](https://github.com/googleapis/release-please). See [documentation](https://github.com/googleapis/release-please#release-please). --------- Co-authored-by: release-please[bot] <55107282+release-please[bot]@users.noreply.github.com> Co-authored-by: Yuan Teoh <45984206+Yuan325@users.noreply.github.com> d67cfbe
🤖 I have created a release *beep* *boop* --- ## [1.4.0](googleapis/mcp-toolbox@v1.3.0...v1.4.0) (2026-06-04) ### Features * **ci:** Add support for windows/arm64 binary distribution ([googleapis#3231](googleapis#3231)) ([10abf3b](googleapis@10abf3b)) * **datalineage:** Add Data Lineage integration ([googleapis#3285](googleapis#3285)) ([19353c3](googleapis@19353c3)) * **server:** Ignore unknown tools at startup with `--ignore-unknown-tools` flag ([googleapis#3353](googleapis#3353)) ([5f0304f](googleapis@5f0304f)) * **tools/cloudsqlpg:** Add remaining vector assist tools for Cloud SQL Postgres ([googleapis#3203](googleapis#3203)) ([b514cbd](googleapis@b514cbd)) * **tools/spanner-search-catalog:** Implement search_catalog tool ([googleapis#3140](googleapis#3140)) ([defc086](googleapis@defc086)) ### Bug Fixes * **auth/generic:** Enforce issuer presence in opaque token validation ([googleapis#3360](googleapis#3360)) ([1d8df0d](googleapis@1d8df0d)) * **auth:** Separate Google and Generic MCP OAuth verification ([googleapis#3341](googleapis#3341)) ([dfd66ee](googleapis@dfd66ee)) * **mcp:** Support annotations and metadata within Tools to earlier MCP schemas ([googleapis#3300](googleapis#3300)) ([9a88c72](googleapis@9a88c72)) * **oracle:** Remove trailing semicolons from prebuilt tools ([googleapis#3215](googleapis#3215)) ([fcad02d](googleapis@fcad02d)) * **server/auth:** Centralize tool scopes validation ([googleapis#3335](googleapis#3335)) ([adce4ab](googleapis@adce4ab)) * **server:** Return null id for batch request rejection ([googleapis#3333](googleapis#3333)) ([0b18d58](googleapis@0b18d58)) * **source/dataplex:** Limit search results to pageSize ([googleapis#3323](googleapis#3323)) ([905c1f6](googleapis@905c1f6)), closes [googleapis#3308](googleapis#3308) * **telemetry:** Allow GCP project override ([googleapis#2960](googleapis#2960)) ([3c83ba5](googleapis@3c83ba5)) * **tool/bigquery:** Prevent `allowedDatasets` bypass in forecast query ([googleapis#3324](googleapis#3324)) ([45df461](googleapis@45df461)) * **tool/clickhouse:** Handle ignored ProcessParameters error ([googleapis#3340](googleapis#3340)) ([ddfd887](googleapis@ddfd887)) * **tools/clickhouse,tools/bigquery:** Validate identifier parameters to prevent injection ([googleapis#3219](googleapis#3219)) ([2f45f75](googleapis@2f45f75)) * **tools/looker:** Escape filter values for unquoted parameters ([googleapis#3289](googleapis#3289)) ([1711156](googleapis@1711156)) --- This PR was generated with [Release Please](https://github.com/googleapis/release-please). See [documentation](https://github.com/googleapis/release-please#release-please). --------- Co-authored-by: release-please[bot] <55107282+release-please[bot]@users.noreply.github.com> Co-authored-by: Yuan Teoh <45984206+Yuan325@users.noreply.github.com> d67cfbe
Addressing vulnerabilities in
bigquery-analyze-contributionandbigquery-forecasttools.Reported by: Matteo Panzeri