Skip to content

feat(oracledb): add Oracle Database integration - #7378

Merged
waleedlatif1 merged 2 commits into
stagingfrom
feat/oracledb-integration
Oct 8, 2026
Merged

waleedlatif1 merged 2 commits into
stagingfrom
feat/oracledb-integration

Conversation

@BillLeoutsakosvl346

@BillLeoutsakosvl346 BillLeoutsakosvl346 commented Sep 2, 2026 •

Copy link
Copy Markdown
Contributor

Adds Oracle Database query, execute, insert, update, delete, and introspection tools backed by a reusable saved connection. Users connect or reconnect through the shared Integrations credential modal; the connection is verified before encryption, and tools receive only an authorized credential reference.

Oracle Net runs through a bounded Node 24 Thin-driver worker and a request-scoped egress proxy. Every initial and redirected destination is validated and pinned. TCPS verifies the hostname and certificate, supports encrypted in-memory PEM wallets, and cannot downgrade to TCP. Results preserve NUMBER precision and stream bounded LOBs; queries run in read-only transactions, and writes autocommit.

No shared OAuth app, new Oracle-specific deployment secret, or database migration is required. The application runtime needs network access to the customer database. Docker and Trigger packaging include the pinned, verified Oracle driver and worker.

Validation:

  • Rebased onto staging; validate-integration, memory-load review, credential UI review, and test audit completed.
  • Lint, all 26 workspace type checks, all 58 audits, docs manifest, and block-registry gates pass.
  • 233 focused tests pass, covering Oracle execution, saved credentials, and deployment availability.
  • Nine real Oracle Database Free 23.26 checks pass through the production proxy and worker: credential verification/encryption, DDL, bound CRUD, precision and CLOB handling, introspection, and read-only mutation denial.
  • Four additional transport checks pass through a local mutual-TLS relay: encrypted-wallet query success, hostname-mismatch denial, wrong-wallet-password denial, and untrusted-certificate denial. This does not claim an Oracle Cloud tenancy test.
  • Full app suite: 36,738 tests pass (25 skipped) under Node 24 with four workers. Root script tests and the other 19 workspace test tasks passed in the repository run.
  • All CI checks pass on the final rebased revision, including lint, both test shards, all eight database-integration shards, API end-to-end tests, the production build, and both desktop suites. There are no unresolved review threads.

@BillLeoutsakosvl346
BillLeoutsakosvl346 requested a review from a team as a code owner September 2, 2026 01:10
@vercel

vercel Bot commented Sep 2, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
docs Ready Ready Preview Oct 8, 2026 7:57pm UTC

Request Review

@greptile-apps

greptile-apps Bot commented Sep 2, 2026

Copy link
Copy Markdown
Contributor

Greptile Summary

Adds an Oracle Database integration with query, mutation, execution, and schema-introspection operations.

  • Introduces validated Oracle connection schemas, SQL construction and classification, bounded result normalization, and an isolated Node 24 worker.
  • Routes initial connections and listener redirects through a request-scoped validating CONNECT proxy.
  • Registers the block and tools across runtime, generated metadata, documentation, deployment configuration, and icon catalogs.
  • Packages and verifies the pinned, patched oracledb@7.0.1 driver in Docker and Trigger.dev environments.

Confidence Score: 5/5

The PR appears safe to merge based on the reviewed implementation and its coordinated runtime packaging.

No concrete changed-code failure remained after tracing SQL execution, connection and redirect validation, worker lifecycle, secret transport, result bounds, and deployment artifact resolution.

Important Files Changed

Filename Overview
apps/sim/lib/internal/oracledb/connect-proxy.ts Adds a request-scoped CONNECT proxy that validates and pins every initial or redirected Oracle target while bounding tunnel use.
apps/sim/lib/internal/oracledb/client.ts Adds bounded worker admission, cancellation, timeout handling, proxy lifecycle management, and child-process protocol execution.
apps/sim/lib/internal/oracledb/oracle-worker.cjs Implements Thin-mode connection setup, runtime patch verification, statement execution, LOB streaming, normalization, limits, and secret-safe error projection.
apps/sim/lib/internal/oracledb/query.ts Adds Oracle-aware SQL scanning, operation validation, identifier quoting, structured DML generation, and WHERE-expression safeguards.
apps/sim/lib/internal/oracledb/introspection.ts Adds bounded dictionary-view introspection for visible schemas, tables, columns, constraints, and indexes.
apps/sim/lib/internal/oracledb/schema.ts Defines strict bounded contracts for connection settings, credentials, wallet data, SQL, binds, and structured operations.
patches/oracledb@7.0.1.patch Extends the pinned driver to preserve proxy trust across redirects, support controlled TCP tunneling, and reject transport changes.
docker/app.Dockerfile Packages Node 24, the complete patched Oracle driver, worker, and verification scripts into the production image.
apps/sim/trigger.config.ts Selects Node 24 and includes the worker, verification scripts, driver package, and package metadata in Trigger.dev artifacts.
apps/sim/blocks/blocks/oracledb.ts Defines the Oracle workflow block, six operations, protected connection fields, operation-specific inputs and outputs, templates, and skills.

Sequence Diagram

sequenceDiagram
  participant C as Workflow or Agent
  participant T as Oracle Tool
  participant P as CONNECT Proxy
  participant W as Node 24 Worker
  participant O as Oracle Database
  C->>T: Invoke query, execute, mutation, or introspection
  T->>P: Start request-scoped loopback proxy
  T->>W: Send credentials and statements over stdin
  W->>P: CONNECT initial Oracle target
  P->>P: Resolve, validate, and pin target IP
  P->>O: Open TCP or TCPS tunnel
  opt Listener redirect
    W->>P: CONNECT redirected target
    P->>P: Revalidate and pin redirected IP
    P->>O: Open replacement tunnel
  end
  W->>O: Execute bounded statement batch
  O-->>W: Rows or affected count
  W-->>T: Bounded normalized JSON
  T-->>C: Structured tool result
  T->>P: Close proxy and tunnels
Loading

Reviews (1): Last reviewed commit: "feat(oracledb): add Oracle Database inte..." | Re-trigger Greptile

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All reported issues were addressed across 56 files

Heads up: you’re close to your included review allowance. Set a flex budget so reviews don’t pause.

Re-trigger cubic

Comment thread apps/docs/components/icons.tsx Outdated
Comment thread apps/sim/package.json Outdated
Comment thread packages/deployment-config/src/integrations.json Outdated
Comment thread apps/sim/lib/internal/oracledb/query.ts
Comment thread apps/sim/tools/oracledb/types.ts Outdated
Comment thread apps/sim/components/icons.tsx Outdated
@BillLeoutsakosvl346

Copy link
Copy Markdown
Contributor Author

@cubic-dev-ai review this PR again after commit 7c247da. The six prior threads have been addressed and resolved; please perform a fresh review of the updated diff.

@cubic-dev-ai

cubic-dev-ai Bot commented Sep 2, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai review this PR again after commit 7c247da. The six prior threads have been addressed and resolved; please perform a fresh review of the updated diff.

@BillLeoutsakosvl346 I have started the AI code review. It will take a few minutes to complete.

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All reported issues were addressed across 58 files

Reply with feedback, questions, or to request a fix.

Fix all with cubic | Re-trigger cubic

Comment thread apps/sim/lib/internal/oracledb/query.ts
@BillLeoutsakosvl346

Copy link
Copy Markdown
Contributor Author

@cubic-dev-ai please review this PR again after b28b751. The prior constant-only Oracle WHERE finding is fixed, independently validated, and its thread is resolved.

@cubic-dev-ai

cubic-dev-ai Bot commented Sep 2, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai please review this PR again after b28b751. The prior constant-only Oracle WHERE finding is fixed, independently validated, and its thread is resolved.

@BillLeoutsakosvl346 I have started the AI code review. It will take a few minutes to complete.

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All reported issues were addressed across 58 files

Reply with feedback, questions, or to request a fix.

Fix all with cubic | Re-trigger cubic

Comment thread apps/sim/lib/internal/oracledb/query.ts
@BillLeoutsakosvl346

Copy link
Copy Markdown
Contributor Author

@cubic-dev-ai please review this PR again at b28b751. The latest function-tautology thread was reproduced, answered with repository-contract and cross-database evidence, and resolved as intentionally out of scope; please perform a fresh review and account for that rationale.

@cubic-dev-ai

cubic-dev-ai Bot commented Sep 2, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai please review this PR again at b28b751. The latest function-tautology thread was reproduced, answered with repository-contract and cross-database evidence, and resolved as intentionally out of scope; please perform a fresh review and account for that rationale.

@BillLeoutsakosvl346 I have started the AI code review. It will take a few minutes to complete.

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 58 files

Confidence score: 5/5

  • Automated review surfaced no issues in the provided summaries.
  • No files require special attention.

Re-trigger cubic

@waleedlatif1
waleedlatif1 force-pushed the feat/oracledb-integration branch from 48bd29f to 9c9c272 Compare October 8, 2026 19:52
@waleedlatif1
waleedlatif1 merged commit e3bf8be into staging Oct 8, 2026
56 checks passed

This branch was successfully deployed

1 active deployment
Preview — 9c9c2725 Deployed Oct 8, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants