apache / apache/datafusion-sqlparser-rs
Improve fmt::Display for AST to IntoSql separating the SQL statement and values.
- 主要語言
- Rust
- 星號
- 3.5k
- 分支
- 772
- 平均合併
- 4 天 9 小時
- 30 天內合併 PR
- 17
描述
The current implementation of converting the AST into SQL statement is using the `fmt::Display` trait which creates a string. With it, all the Value expression is embedded into the generated SQL string. This could potentially be used for SQL injection attacks. I believe this needs improvement and the simplest way to do it is to separate the values from the rest of the generated SQL leaving parameter binding in place of that value.
A simple trait to be used would be like:
```rust
trait IntoSql{
into_sql(&self) -> (String, Vec);
}
```
It will be up to the underlying SQL statement executor to supply the values.
Pros:
- Strong mitigation against SQL injection attack.
Cons:
- different SQL dialect may have different syntax with parameter binding, ie: `$1`,`?`, `:var1`
貢獻指南
這個儲存庫沒有索引到貢獻指南
研究方向
Start by locating the AST-to-SQL implementation that uses fmt::Display and the SQL statement executor mentioned in the issue. Review how Value expressions are currently embedded, then determine how parameter binding should represent values across SQL dialects. Done means the AST can produce a statement and separate values without embedding them directly in SQL.
由索引模型根據 Issue 內容生成。
評估
- 技術堆疊
- rust
- 領域
- compilers, databases
- Issue 類型
- 功能
- 難度
- 5/5
- 預估耗時
- 一週以上
- 活躍度
- 停滯
- 描述清晰度
- 基本清楚
- 新手友好度
- 25/100