apache / apache/datafusion-sqlparser-rs

Improve fmt::Display for AST to IntoSql separating the SQL statement and values.

Offen
#282 0 Kommentare 0 Reaktionen 0 zugewiesene Personen Auf GitHub ansehen
Vorherrschende Sprache
Rust
Sterne
3.5k
Forks
772
Ø Merge
4 T. 9 Std.
Gemergte PRs (30 T.)
17

Beschreibung

The current implementation of converting the AST into SQL statement is using the `fmt::Display` trait which creates a string. With it, all the Value expression is embedded into the generated SQL string. This could potentially be used for SQL injection attacks. I believe this needs improvement and the simplest way to do it is to separate the values from the rest of the generated SQL leaving parameter binding in place of that value.

A simple trait to be used would be like:

```rust
trait IntoSql{
into_sql(&self) -> (String, Vec);
}
```
It will be up to the underlying SQL statement executor to supply the values.

Pros:
- Strong mitigation against SQL injection attack.

Cons:
- different SQL dialect may have different syntax with parameter binding, ie: `$1`,`?`, `:var1`

Beitragsleitfaden

Für dieses Repository ist kein Beitragsleitfaden indexiert

Rechercherichtung

Start by locating the AST-to-SQL implementation that uses fmt::Display and the SQL statement executor mentioned in the issue. Review how Value expressions are currently embedded, then determine how parameter binding should represent values across SQL dialects. Done means the AST can produce a statement and separate values without embedding them directly in SQL.

Vom Indexierungsmodell aus dem Issue-Text verfasst.

Bewertung

Tech-Stack
rust
Bereich
compilers, databases
Issue-Typ
Feature
Schwierigkeit
5/5
Geschätzter Aufwand
Über eine Woche
Aktivitätsstatus
Veraltet
Klarheit
Größtenteils klar
Anfängerfreundlichkeit
25/100

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.