inspec/docs/resources/postgres_session.md.erb

70 lines
1.8 KiB
Text
Raw Normal View History

2016-09-22 12:43:57 +00:00
---
title: About the postgres_session Resource
platform: os
2016-09-22 12:43:57 +00:00
---
# postgres_session
Use the `postgres_session` InSpec audit resource to test SQL commands run against a PostgreSQL database.
<br>
## Syntax
2016-09-22 12:43:57 +00:00
A `postgres_session` resource block declares the username and password to use for the session, and then the command to be run:
# Create a PostgreSQL session:
sql = postgres_session('username', 'password', 'host')
2016-09-22 12:43:57 +00:00
# default values:
# username: 'postgres'
# host: 'localhost'
# Run an SQL query with an optional database to execute
sql.query('sql_query', ['database_name'])`
A full example is:
sql = postgres_session('username', 'password', 'host')
2016-09-22 12:43:57 +00:00
describe sql.query('SELECT * FROM pg_shadow WHERE passwd IS NULL;') do
its('output') { should eq '' }
2016-09-22 12:43:57 +00:00
end
where `its('output') { should eq '' }` compares the results of the query against the expected result in the test
2016-09-22 12:43:57 +00:00
<br>
2016-09-22 12:43:57 +00:00
## Examples
2016-09-22 12:43:57 +00:00
The following examples show how to use this InSpec audit resource.
### Test the PostgreSQL shadow password
2016-09-22 12:43:57 +00:00
sql = postgres_session('my_user', 'password', '192.168.1.2')
2016-09-22 12:43:57 +00:00
describe sql.query('SELECT * FROM pg_shadow WHERE passwd IS NULL;', ['testdb']) do
2016-09-22 12:43:57 +00:00
its('output') { should eq('') }
end
### Test for risky database entries
2016-09-22 12:43:57 +00:00
describe postgres_session('my_user', 'password').query('SELECT count (*)
FROM pg_language
WHERE lanpltrusted = \'f\'
AND lanname!=\'internal\'
AND lanname!=\'c\';', ['postgres']) do
2016-09-22 12:43:57 +00:00
its('output') { should eq '0' }
end
<br>
## Matchers
For a full list of available matchers please visit our [matchers page](https://www.inspec.io/docs/reference/matchers/).
### output
The `output` matcher tests the results of the query:
its('output') { should eq(/^0/) }