Commit 797594a
oraclemcp P1-POLICY: per-schema scoping & allow/deny policy (§6.2)
Bead oracle-qmwz.2.19. oraclemcp-guard policy.rs: SchemaPolicySet.evaluate ->
Deny/Allow that only ever further-restricts the classifier (never loosens).
TOML SchemaPolicyRaw (default_mode/allow_dml/deny_ddl/deny_all/deny_patterns);
SYS/SYSTEM/SYSAUX/AUDSYS/DBSNMP always deny-all; unknown schema reads pass,
mutations deny-by-default. 6 tests; clippy -D warnings + fmt clean.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>1 parent 0a3092f commit 797594a
3 files changed
Lines changed: 292 additions & 1 deletion
0 commit comments