sqlite: expose connection authorizer
Related to #256 (closed)
This is intentionally a draft. It provides a concrete implementation of sqlite3_set_authorizer support so the API and implementation can be discussed against working code.
Summary
The proposal exposes SQLite's connection-scoped authorizer through database/sql.Conn.Raw.
It adds:
AuthorizerActionCodeand the SQLite authorizer action constants;AuthorizerReturnCodeforOK,DENY, andIGNORE;AuthorizerFn; andAuthorizerRegisterer.RegisterAuthorizer.
The authorizer belongs on the physical SQLite connection, so Conn.Raw is the natural boundary. A non-nil callback installs or replaces the authorizer; nil removes it. It remains associated with that physical connection across pool reuse.
I used a separate AuthorizerRegisterer interface rather than extending HookRegisterer, because adding a method to an existing exported interface would change its method set.
The patch also updates the _defensive documentation, which currently notes that the driver does not expose an authorizer. The authorizer remains opt-in; this does not turn _defensive into a sandbox for untrusted databases.
Validation
Tests cover registration/replacement/removal, OK/DENY/IGNORE, callback arguments including trigger context, automatic reprepare after schema changes, pool reuse, close cleanup, and independent concurrent connections.
With Go 1.25.9 on linux/amd64:
go test -count=1 -run 'Authorizer' . PASS
go test -race -count=1 -run 'Authorizer' . PASS
go test -count=1 ./... PASS
make build_all_targets PASSNo generated SQLite source is modified.
The exported names and exact API shape are deliberately a working proposal. I am happy to reshape them to fit the project if the capability itself is useful.
For transparency: I worked out the requirement and reviewed the design and implementation, but I used OpenAI Codex to write much of the patch and tests. I reviewed the resulting diff and validation and I am responsible for the submission.