{
"event": "PreToolUse",
"tool_name": "Edit",
"tool_input": {
"file_path": "\/var\/www\/mcp-servers\/mcp-db\/tools\/update_tool.py",
"old_string": "sys.path.insert(0, \"\/opt\/mcp-servers\/mcp-db\")",
"new_string": "sys.path.insert(0, \"\/opt\/mcp-servers\/mcp-db\")\nsys.path.insert(0, \"\/var\/www\/mcp-servers\/shared\")\n\nfrom constants import LOG_ENTRY_MAX_LENGTH, LOG_QUERY_MAX_LENGTH, MS_PER_SECOND"
}
}
{
"tool_response": {
"filePath": "\/var\/www\/mcp-servers\/mcp-db\/tools\/update_tool.py",
"oldString": "sys.path.insert(0, \"\/opt\/mcp-servers\/mcp-db\")",
"newString": "sys.path.insert(0, \"\/opt\/mcp-servers\/mcp-db\")\nsys.path.insert(0, \"\/var\/www\/mcp-servers\/shared\")\n\nfrom constants import LOG_ENTRY_MAX_LENGTH, LOG_QUERY_MAX_LENGTH, MS_PER_SECOND",
"originalFile": "\"\"\"Update Tool - Aktualisiert Datensätze.\"\"\"\nimport re\nimport sys\nimport time\n\nsys.path.insert(0, \"\/opt\/mcp-servers\/mcp-db\")\n\nfrom config import Config\nfrom domain.log_contract import LogEntry\nfrom infrastructure.db_connection import DatabaseConnection\nfrom infrastructure.protokoll_logger import ProtokollLogger\n\n\ndef _validate_identifier(name: str) -> bool:\n \"\"\"Validiert Tabellen-\/Spaltennamen gegen SQL-Injection.\"\"\"\n return bool(re.match(r\"^[a-zA-Z0-9_]+$\", name))\n\n\ndef register_update_tool(mcp) -> None:\n \"\"\"Registriert db_update Tool.\"\"\"\n logger = ProtokollLogger()\n\n @mcp.tool()\n def db_update(\n table: str,\n data: dict,\n where: dict,\n database: str = \"ki_dev\",\n ) -> dict:\n \"\"\"\n Aktualisiert Datensätze.\n\n Args:\n table: Zieltabelle\n data: Dict mit Spalte:Wert Paaren (SET-Klausel)\n where: Dict mit Spalte:Wert Paaren (WHERE-Klausel) - PFLICHT!\n database: Zieldatenbank (ki_dev oder ki_content)\n\n Returns:\n Dict mit status, affected_rows, error\n \"\"\"\n start = time.time()\n\n # Validierung: Tabellenname\n if not _validate_identifier(table):\n return {\n \"status\": \"denied\",\n \"error\": \"Invalid table name.\",\n }\n\n # Validierung: Datenbank\n if database not in Config.ALLOWED_DATABASES:\n return {\n \"status\": \"denied\",\n \"error\": f\"Database '{database}' not allowed.\",\n }\n\n # Validierung: Data nicht leer\n if not data:\n return {\n \"status\": \"denied\",\n \"error\": \"Data dict must not be empty.\",\n }\n\n # KRITISCH: WHERE ist Pflicht!\n if not where:\n return {\n \"status\": \"denied\",\n \"error\": \"WHERE clause is required. UPDATE without WHERE is forbidden.\",\n }\n\n # Validierung: Spaltennamen in data\n for col in data:\n if not _validate_identifier(col):\n return {\n \"status\": \"denied\",\n \"error\": f\"Invalid column name in data: {col}\",\n }\n\n # Validierung: Spaltennamen in where\n for col in where:\n if not _validate_identifier(col):\n return {\n \"status\": \"denied\",\n \"error\": f\"Invalid column name in where: {col}\",\n }\n\n try:\n with DatabaseConnection.get_connection(database) as conn:\n cursor = conn.cursor(buffered=True)\n\n # Build SET clause\n set_parts = [f\"`{col}` = %s\" for col in data]\n set_clause = \", \".join(set_parts)\n\n # Build WHERE clause\n where_parts = [f\"`{col}` = %s\" for col in where]\n where_clause = \" AND \".join(where_parts)\n\n # Combine values: SET values first, then WHERE values\n values = tuple(data.values()) + tuple(where.values())\n\n query = f\"UPDATE `{table}` SET {set_clause} WHERE {where_clause}\"\n cursor.execute(query, values)\n affected_rows = cursor.rowcount\n conn.commit()\n cursor.close()\n\n duration = int((time.time() - start) * 1000)\n\n # Log\n try:\n logger.log(\n LogEntry(\n request=f\"UPDATE {table} SET ... WHERE ...\",\n status=\"success\",\n duration_ms=duration,\n )\n )\n except Exception:\n pass\n\n return {\n \"status\": \"success\",\n \"table\": table,\n \"affected_rows\": affected_rows,\n \"execution_ms\": duration,\n }\n\n except Exception as e:\n duration = int((time.time() - start) * 1000)\n\n try:\n logger.log(\n LogEntry(\n request=f\"UPDATE {table}\",\n status=\"error\",\n duration_ms=duration,\n error_message=str(e)[:100],\n )\n )\n except Exception:\n pass\n\n return {\n \"status\": \"error\",\n \"error\": str(e)[:200],\n \"execution_ms\": duration,\n }\n",
"structuredPatch": [
{
"oldStart": 4,
"oldLines": 7,
"newStart": 4,
"newLines": 10,
"lines": [
" import time",
" ",
" sys.path.insert(0, \"\/opt\/mcp-servers\/mcp-db\")",
"+sys.path.insert(0, \"\/var\/www\/mcp-servers\/shared\")",
" ",
"+from constants import LOG_ENTRY_MAX_LENGTH, LOG_QUERY_MAX_LENGTH, MS_PER_SECOND",
"+",
" from config import Config",
" from domain.log_contract import LogEntry",
" from infrastructure.db_connection import DatabaseConnection"
]
}
],
"userModified": false,
"replaceAll": false
}
}