T09 · Insecure Skill Coding Practices
- Location
database.py:17- Finding
SQLite Foreign-Key Constraints Are Not Enforced
- Content
View full analysis
bool: """ Delete a person from the database. Returns: True if the person was deleted, False otherwise """ self.cursor.execute("DELETE FROM people WHERE id = ?", (person_id,)) self.connection.commit() return self.cursor.rowcount > 0 ``` ### Technical Analysis SQLite disables foreign-key enforcement by default for each database connection. Declaring `FOREIGN KEY` constraints in the schema does not activate them. The connection setup never executes: ```sql PRAGMA foreign_keys = ON ``` As a result, the application can insert relationship edges referencing nonexistent people. Additionally, deleting a person does not reliably trigger the declared `ON DELETE CASCADE` actions, leaving orphaned relationship records in the `edges` table. This behavior contradicts the documented guarantees that foreign-key constraints prevent invalid relationships and that deleting a person removes all associated relationships. Parameterized SQL prevents SQL injection here, but it does not compensate for disabled referential-integrity controls. ### Attack Path 1. A caller invokes `add_relationship` with one or both pers ...[truncated 1312 chars]- Remediation
View remediation
