Explicit safety boundary
Local only unless the build opts in.
The default build processes every value in this tab, omits connected routes and Turnstile, and enforces connect-src 'none'.
Local-only profile
Formatting, decoding, hashing, parsing, generation, and calculation use bundled browser code. Uploaded JWT verification keys stay in tab memory; supplied code is parsed but never executed.
Public documentation and crawlers
Canonical tool, category, privacy, security, terms, and about pages are intentionally crawlable. Tool input and output are never copied into titles, descriptions, structured data, sitemaps, analytics, or canonical URLs. Google's obsolete meta-keywords tag is intentionally omitted; search intent is expressed only through accurate visible content. Public guide links to mysql.odmin.biz contain no launcher, demo, connection, credential, or bearer value and navigate only after a user click.
Connected profile
Every network operation needs an explicit click. Each DNS, protected server HTTP, TCP, and TLS diagnostic request needs a fresh Turnstile token that is verified before any destination request and cleared after the attempt. MySQL requires fresh verification before every connection; later structured reads are accepted only inside that verified session, never as standalone public requests. Direct HTTP GET/HEAD uses the visitor's browser instead, omits credentials, and remains subject to CORS.
HTTP request boundary
The optional cURL/fetch importer parses one static copied request locally without evaluating JavaScript or shell text and never sends automatically. It rejects expressions, files, multipart data, command chains, and multiple URLs; drops credential, cookie, proxy, forwarding, framing, and reserved browser fields with visible warnings; clears the pasted source after a successful apply; and selects protected Server request mode. Exporting cURL/fetch text also remains local. Browser mode supports HTTP or HTTPS GET and HEAD only. Server request mode—and every POST, PUT, PATCH, DELETE, or OPTIONS request—uses exact https://http-client.odmin.biz/ after Turnstile and accepts public HTTP or HTTPS only on its default port. Every hop resolves through fixed DNS, rejects any private or reserved answer, and pins one checked address. HTTPS connects with Node TLS to that pinned address while using the original URL hostname as the mandatory public-certificate identity; certificate verification cannot be disabled and no fallback occurs. The exact request line, generated and custom headers, separators, and UTF-8 text body share one 16 KiB limit. Server mode may set bounded Referer and User-Agent values plus one syntactically valid HTTP(S) Origin; that outbound field is separate from the exact browser Origin authenticated by the gateway. Files, multipart upload fields, credentials, cookies, forwarding fields, and transport-sensitive or reserved browser headers remain blocked. Redirect following is GET/HEAD-only, stops after five hops, repeats every destination check, and removes custom headers across origins. The optional HTML response preview is sandboxed and strips scripts, styles, forms, links, media, and remote resources before rendering.
TCP check boundary
/port-api accepts one public hostname or IP, rejects private or reserved addresses, opens one checked TCP address for at most five seconds, sends no application bytes, waits up to one second for at most 4 KiB of server-first banner data, and closes immediately. Its telnet-style transcript strips control characters. It cannot accept a port range, list, client payload, or interactive stream. Five concurrent checks per IP per isolate is best-effort abuse resistance.
TLS diagnostic boundary
The TLS checker sends exact operation=tls, one public hostname or IP, one integer port, and a fresh tls_diagnostic token to exact https://http-client.odmin.biz/. The gateway rejects private or reserved destinations, pins one checked address, requires TLS 1.2 or newer with public trust and server-identity verification, sends no application data, and closes after the attempt. It returns only bounded connection and negotiation metadata, a closed sanitized failure description and applicable TLS alert number, and at most eight peer certificates within a 96 KiB DER cap. A refused connection, timeout, verification error, or TLS alert is displayed as a failed OpenSSL-style diagnostic; any peer certificate observed on that path is labeled unverified and is never accepted to continue the connection. There is no insecure mode, custom trust anchor, automatic fallback, port list, or general TLS proxy.
MySQL connection boundary
Your browser opens the canonical MySQL page at https://odmin.biz/tools/mysql-client and connects to the odmin.biz MySQL gateway at wss://mysql2.odmin.biz/ using authenticated WSS/TLS. That endpoint accepts upgrades only from exact production browser origin https://odmin.biz. Fresh Turnstile is mandatory for every user or Real-demo connection and every SSH tunnel diagnostic, and its verdict hostname must match exact page host odmin.biz. A live session ends after fifteen minutes of inactivity or after one hour total, whichever comes first; reconnecting always requires a new challenge. Direct mode opens a connection to one selected public MySQL host and port, rejects any hostname with a private or reserved answer, and pins one checked address. User SSH mode instead resolves and pins one public SSH endpoint with a configurable port, uses a browser-held Ed25519 or RSA private key to sign a validated authentication challenge, and opens exactly one MySQL forwarding channel to the target as seen from that SSH server. A supplied SHA-256 host-key pin is enforced; without one, the observed fingerprint is shown in a per-attempt acknowledgment dialog before any signature. Your selected private key and passphrase never leave your machine. Only the public key, observed fingerprint, bounded challenge, and signature transit WSS. Because the SSH session identifier is opaque to browser code, the reviewed gateway remains trusted to bind the challenge to the selected host. Test SSH tunnel authenticates and opens that exact channel, then closes it without sending MySQL bytes or creating a shell/session channel. Test database connection performs the ordinary selected transport, read-only session setup, and initial metadata read, then closes. Both diagnostics preserve the browser-only key for retry. SSH mode exposes no password authentication, silent fingerprint bypass, shell, command, SFTP, agent-forwarding, remote-forwarding, or arbitrary stream operation.
The recommended Real demo is a separate fixed backend connection. Its destination, dedicated read-only MySQL credentials, and optional dedicated SSH key come only from an owner-managed Kubernetes Secret and cannot be supplied or overridden by the browser. A backend SSH key signs inside the Node gateway and never enters the frontend or WSS. Omitting that Secret makes the Real demo fail closed; the Sample data option remains entirely local and contacts neither the gateway nor a database.
Verified MySQL TLS 1.2 or newer with public trust and server-identity verification remains the default on both routes. The optional advanced certificate hostname remains available when an SSH target such as 127.0.0.1 differs from the public certificate identity. The user may explicitly select TLS without verification or plaintext only after acknowledging a warning on every attempt; an unsafe Real-demo mode must instead be an explicit deployment-owner configuration. Neither unsafe mode weakens the browser-to-gateway connection or SSH encryption, but an unpinned SSH identity is only as trustworthy as the fingerprint accepted for that attempt, and plaintext MySQL has no separate protection beyond the SSH server. There is no automatic fallback and custom CA fields remain unavailable. The protocol exposes metadata, bounded row pages, explicit exact row counts, and bounded server-generated database and object definitions through opaque IDs—never browser-supplied SQL or mutations. Exact COUNT(*) runs only after the user presses the count control and remains subject to the query timeout; it is not part of row preview. Clicking a discovered database, table, view, routine, event, or trigger may request its bounded SHOW CREATE result; the browser cannot supply the object name. Once a group is fetched, its exact loaded child count is displayed without another query.
Full hosted demo boundary
Adminer, phpMyAdmin, DbGate, CloudBeaver, and MySQL Shell GUI are separate full community tools hosted in isolated mysql.odmin.biz workloads. Production is the missing-variable default; a local or hosted staging build may instead select only exact mysql-staging.odmin.biz, and arbitrary domains fail the build. The connected static export embeds no catalog or demo URL. After hydration, the browser reads the exact selected-origin live catalog immediately and whenever the page regains focus or visibility, without cache, credentials, a referrer, or background polling; it disables every existing link before each read. Only exact random per-tool HTTPS hostnames under the same selected domain are accepted, and missing, invalid, or unavailable responses leave images disabled. Opening an enabled image is an explicit navigation to a new tab. All five use the same dedicated non-sensitive read-only Sakila account, but the full tool software and hosting infrastructure remain separate trust boundaries. Do not enter private data.
The private-instance action does not expose its launcher in the original page. After a visitor clicks Check availability, a fresh Turnstile token with action availability is sent by itself to exact https://mysql.odmin.biz/api/availability with credentials omitted. Only a positive bounded capacity result can reveal a launcher action at that exact origin root held in current-tab memory. Retrying requires a new challenge.
Read-only defense in depth
The Kubernetes gateway sets the session transaction mode to read-only, but a dedicated read-only MySQL account remains required. Generated operation labels and user-expandable debug results capped at 32 KiB per entry remain only in current-session browser memory. The selected server may log authentication and generated reads.
Permanent boundary
New tools remain browser-only unless their requirements explicitly authorize and document a narrow destination, schema, trigger, retention model, abuse controls, CSP, deployment route, and tests.