apache / apache/datafusion-sqlparser-rs
Improve fmt::Display for AST to IntoSql separating the SQL statement and values.
- 主要语言
- Rust
- 星标
- 3.5k
- 派生
- 772
- 平均合并
- 4 天 9 小时
- 30 天内合并 PR
- 17
描述
The current implementation of converting the AST into SQL statement is using the `fmt::Display` trait which creates a string. With it, all the Value expression is embedded into the generated SQL string. This could potentially be used for SQL injection attacks. I believe this needs improvement and the simplest way to do it is to separate the values from the rest of the generated SQL leaving parameter binding in place of that value.
A simple trait to be used would be like:
```rust
trait IntoSql{
into_sql(&self) -> (String, Vec);
}
```
It will be up to the underlying SQL statement executor to supply the values.
Pros:
- Strong mitigation against SQL injection attack.
Cons:
- different SQL dialect may have different syntax with parameter binding, ie: `$1`,`?`, `:var1`
贡献指南
这个仓库没有索引到贡献指南
调研方向
Start by locating the AST-to-SQL implementation that uses fmt::Display and the SQL statement executor mentioned in the issue. Review how Value expressions are currently embedded, then determine how parameter binding should represent values across SQL dialects. Done means the AST can produce a statement and separate values without embedding them directly in SQL.
由索引模型根据 Issue 内容生成。
评估
- 技术栈
- rust
- 领域
- compilers, databases
- Issue 类型
- 功能
- 难度
- 5/5
- 预计耗时
- 一周以上
- 活跃度
- 停滞
- 描述清晰度
- 基本清楚
- 新手友好度
- 25/100