2 Commits

Author SHA1 Message Date
Alex Dunmow
40d33d0587 rawsql: allow FROM pg_roles admin catalog lookup
The wasm per-plugin role provisioner (cms role_provisioner.go, WO-WZ-007)
checks role existence with a parameterized `SELECT ... FROM pg_roles`.
That is a Postgres administrative catalog lookup (DCL provisioning, not
sqlc-able), the same category as the already-allowed `FROM pg_database`.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-03 16:36:58 +08:00
Alex Dunmow
cd88c808b0 initial: standalone check-safety module hoisted from CMS
Static safety/lint runner for the BlockNinja codebase. ~25 invariant
checks across Go and frontend sources. Was at git.dev.alexdunmow.com:block/ninja
in backend/cmd/check-safety/ until the 2026-06-06 consolidation moved
the BlockNinja repos under a shared ~/src/blockninja/ parent.

This repo is the standalone extraction:
- Own go.mod (git.dev.alexdunmow.com/block/check-safety, go 1.26.4)
- Vendored internal/{helpers,theme} from CMS (Go's internal/ rule
  blocks cross-module imports; vendoring is the workaround)
- CLI contract unchanged: `check-safety <target-dir> [--flags]`
- CMS Makefile shells into ../check-safety for safety-check /
  install-safety-checker targets

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
2026-06-06 13:04:02 +08:00