Research
Security News
Malicious npm Packages Inject SSH Backdoors via Typosquatted Libraries
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
database_rewinder is a minimalist's tiny and ultra-fast database cleaner.
database_rewinder memorizes every table name into which INSERT
SQL was performed during each test case.
Then it executes DELETE
SQL only against these tables when cleaning.
So, the more number of tables you have in your database, the more benefit you will get.
Also, database_rewinder joins all DELETE
SQL statements and casts it in one DB server call.
This strategy was originally devised and implemented by Shingo Morita (@eudoxa) at COOKPAD Inc.
ActiveRecord 4.2, 5.0, 5.1, 5.2, 6.0, 6.1, 7.0, 7.1, 7.2 (edge)
Ruby 2.4, 2.5, 2.6, 2.7, 3.0, 3.1, 3.2, 3.3 (trunk)
Add this line to your Gemfile's :test
group:
gem 'database_rewinder'
And then execute:
$ bundle
Do clean
in after(:each)
. And do clean_all
or clean_with
in before(:suite)
if you'd like to.
RSpec.configure do |config|
config.before(:suite) do
DatabaseRewinder.clean_all
# or
# DatabaseRewinder.clean_with :any_arg_that_would_be_actually_ignored_anyway
end
config.after(:each) do
DatabaseRewinder.clean
end
end
You can configure multiple DB connections to tell DatabaseRewinder to cleanup all of them after each test.
In order to add another connection, use DatabaseRewinder[]
method.
RSpec.configure do |config|
config.before(:suite) do
# simply give the DB connection names that are written in config/database.yml
DatabaseRewinder['test']
DatabaseRewinder['another_test_db']
# you could give the DB name with connection: key if you like
DatabaseRewinder[connection: 'yet_another_test_db']
# or with a meaningless something first, then {connection: DB_NAME} as the second argument (DatabaseCleaner compatible)
DatabaseRewinder[:active_record, connection: 'an_active_record_db']
DatabaseRewinder.clean_all
end
config.after(:each) do
DatabaseRewinder.clean
end
end
database_rewinder tries to create a new DB connection for deletion when you're running tests on MySQL.
You would occasionally hit some weird errors (e.g. query execution timeout) because of this, especially when your tests are run with the use_transactional_tests
option enabled (which is Rails' default).
use_transactional_tests
means, and consider turning it offuse_transactional_tests
is the option that surrounds each of your test case with a DB transaction to roll back all your test data after each test run.
So far as this works properly, you won't really need to use database_rewinder.
However, this simple mechanism doesn't work well when you're running integration tests with capybara + js mode.
In cases of this situation, bundle database_rewinder and add the following configuration.
RSpec.configure do |config|
config.use_transactional_tests = false
...
end
multiple: false
optionIf you're really sure you need to keep using transactional tests + database_rewinder for some reason, then explicitly pass in multiple: false
option to DatabaseRewinder.clean_all
and DatabaseRewinder.clean
invocations as follows. Note that you won't be able to get full performance merit that database_rewinder provides though.
RSpec.configure do |config|
config.before :suite do
DatabaseRewinder.clean_all multiple: false
end
config.after :each do
DatabaseRewinder.clean multiple: false
end
end
database_rewinder is designed to be almost compatible with database_cleaner. So the following code will probably let your existing app work under database_rewinder without making any change on your configuration.
DatabaseCleaner = DatabaseRewinder
Send me your pull requests.
FAQs
Unknown package
We found that database_rewinder demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
Security News
MITRE's 2024 CWE Top 25 highlights critical software vulnerabilities like XSS, SQL Injection, and CSRF, reflecting shifts due to a refined ranking methodology.
Security News
In this segment of the Risky Business podcast, Feross Aboukhadijeh and Patrick Gray discuss the challenges of tracking malware discovered in open source softare.