apache / apache/datafusion-sqlparser-rs

Improve fmt::Display for AST to IntoSql separating the SQL statement and values.

未关闭
#282 0 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看
主要语言
Rust
星标
3.5k
派生
772
平均合并
4 天 9 小时
30 天内合并 PR
17

描述

The current implementation of converting the AST into SQL statement is using the `fmt::Display` trait which creates a string. With it, all the Value expression is embedded into the generated SQL string. This could potentially be used for SQL injection attacks. I believe this needs improvement and the simplest way to do it is to separate the values from the rest of the generated SQL leaving parameter binding in place of that value.

A simple trait to be used would be like:

```rust
trait IntoSql{
into_sql(&self) -> (String, Vec);
}
```
It will be up to the underlying SQL statement executor to supply the values.

Pros:
- Strong mitigation against SQL injection attack.

Cons:
- different SQL dialect may have different syntax with parameter binding, ie: `$1`,`?`, `:var1`

贡献指南

这个仓库没有索引到贡献指南

调研方向

Start by locating the AST-to-SQL implementation that uses fmt::Display and the SQL statement executor mentioned in the issue. Review how Value expressions are currently embedded, then determine how parameter binding should represent values across SQL dialects. Done means the AST can produce a statement and separate values without embedding them directly in SQL.

由索引模型根据 Issue 内容生成。

评估

技术栈
rust
领域
compilers, databases
Issue 类型
功能
难度
5/5
预计耗时
一周以上
活跃度
停滞
描述清晰度
基本清楚
新手友好度
25/100

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。