Class: Inspec::Resources::PostgresSession

Inherits:
Object
  • Object
show all
Defined in:
lib/resources/postgres_session.rb

Instance Method Summary collapse

Constructor Details

#initialize(user, pass) ⇒ PostgresSession

Returns a new instance of PostgresSession.



36
37
38
39
# File 'lib/resources/postgres_session.rb', line 36

def initialize(user, pass)
  @user = user || 'postgres'
  @pass = pass
end

Instance Method Details

#query(query, db = []) ⇒ Object



41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
# File 'lib/resources/postgres_session.rb', line 41

def query(query, db = [])
  dbs = db.map { |x| "-d #{x}" }.join(' ')
  # TODO: simple escape, must be handled by a library
  # that does this securely
  escaped_query = query.gsub(/\\/, '\\\\').gsub(/"/, '\\"').gsub(/\$/, '\\$')
  # run the query
  cmd = inspec.command("PGPASSWORD='#{@pass}' psql -U #{@user} #{dbs} -h localhost -c \"#{escaped_query}\"")
  out = cmd.stdout + "\n" + cmd.stderr
  if cmd.exit_status != 0 or
     out =~ /could not connect to .*/ or
     out.downcase =~ /^error/
    # skip this test if the server can't run the query
    skip_resource "Can't read run query #{query.inspect} on postgres_session: #{out}"
  else
    # remove the whole header (i.e. up to the first ^-----+------+------$)
    # remove the tail
    lines = cmd.stdout
               .sub(/(.*\n)+([-]+[+])*[-]+\n/, '')
               .sub(/\n[^\n]*\n\n$/, '')
    Lines.new(lines.strip, "PostgreSQL query: #{query}")
  end
end