client9 / client9/libinjection

False negative on no whitespace before and/or after "*" or delimited identifier in SELECT list

Open
#152 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
C
Stars
1k
Forks
282
PR merge metrics
No merged PRs in 30d

Description

Little known fact, but at least some SQL dialects, such as T-SQL, don't require whitespace before or after certain characters in the `SELECT` list:

* `*`
* `[`
* `]`
* `(`
* `)`

The following are all completely valid T-SQL and I just confirmed that they all return the expected results without any errors:

```sql
SELECT*FROM sys.objects
SELECT *FROM sys.objects
SELECT* FROM sys.objects

SELECT[name]FROM sys.objects
SELECT [name]FROM sys.objects
SELECT[name] FROM sys.objects

SELECT*,[name]FROM sys.objects
SELECT[name],*FROM sys.objects

SELECT([name])FROM sys.objects
```

P.S. I'm not sure if this behavior relates to Issue #100 or not (in terms of how the `*` is handled).

Take care,
Solomon...
https://SqlQuantumLift.com/
https://SqlQuantumLeap.com/
https://SQLsharp.com/

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.