Repository navigation
fix: quote SQL identifiers in migration generation - #9
Conversation
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 8978872db8
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| .columns | ||
| .iter() | ||
| .map(|c| quote_ident(c, dialect)) | ||
| .collect::<Vec<_>>() |
There was a problem hiding this comment.
Avoid quoting full index clauses in CREATE INDEX
Quoting every entry in idx.columns breaks non-trivial index definitions because these strings are not always bare identifiers. The PostgreSQL loader extracts raw clauses from pg_indexes.indexdef (for example created_at DESC, lower(email), or already-quoted names), and wrapping each clause with quote_ident turns them into invalid or semantically different SQL ("created_at DESC", "lower(email)", etc.). This means migrations generated for expression/sorted indexes can no longer be applied.
Useful? React with 👍 / 👎.
Incorporate MySQL backtick quoting and SQL injection escape test from feat/propose-fix-for-sql-injection-vulnerability. Resolve conflicts keeping our approach: index column clauses are never re-quoted, simple identifiers pass through unquoted for readability.
Motivation
Description
quote_ident(ident: &str, dialect: SqlDialect)andcolumn_definition_sql(col: &Column, dialect: SqlDialect)helpers and used them everywhere migration SQL is constructed instead of raw identifier interpolation.create_table_sqlandcreate_index_sqlto acceptdialect: SqlDialectand to produce quoted/escaped identifiers and quoted column definitions.ALTER TABLE/DROP TABLE/CREATE TABLE/CREATE INDEX/DROP INDEXgeneration sites to call the quoting helpers and stopped usingcol.definition()directly in migration generation.postgres_identifiers_are_quoted_and_escaped) that builds a schema with malicious quoted identifiers to ensure output is escaped and not injectable.Testing
cargo fmt --checkwhich passed after the changes.cargo test -qbut it failed in this environment due to crates.io dependency download being blocked (HTTP 403), so tests could not be executed here.cargo test -q --offlinewhich also failed because some dependencies are not available in the local offline cache, so test execution was not completed in this environment.Codex Task