fix: handle SQL comment side effects, fix injection risk and update query filtering

This commit is contained in:
Monica Khoury committed 2026-04-08 17:44:42 +03:00
1 parent 53c3fd3fce
commit dbeec9a1a5
3 files changed
+10 -9

No files matched your search

@@ -27,7 +27,7 @@ function getCustomRoleImpersonationSql(roleName: string) {
}
// Includes getPostgrestRoleImpersonationSql() and wrapWithRoleImpersonation()
export const ROLE_IMPERSONATION_SQL_LINE_COUNT = 11
export const ROLE_IMPERSONATION_SQL_LINE_COUNT = 13
export const ROLE_IMPERSONATION_NO_RESULTS = 'ROLE_IMPERSONATION_NO_RESULTS'
export const getImpersonationSQL = ({
@@ -1,7 +1,5 @@
export const getOngoingQueriesSql = () => {
const sql = /* SQL */ `
-- source: dashboard
-- description: List currently active queries with PID, query text, and start time
select pid, query, query_start from pg_stat_activity where state = 'active' and datname = 'postgres';
`.trim()
@@ -1,3 +1,5 @@
import { literal, safeSql } from '../../../pg-format'
export const getDeleteBucketPrefixSQL = ({
bucketId,
prefix,
@@ -5,10 +7,11 @@ export const getDeleteBucketPrefixSQL = ({
bucketId: string
prefix: string
}) => {
const sql = /* SQL */ `
-- source: dashboard
-- description: Delete all storage objects matching a prefix within a bucket
select storage.delete_prefix('${bucketId}', '${prefix}');
`.trim()
const sql = safeSql`
-- source: dashboard
-- description: Delete all storage objects matching a prefix within a bucket
select storage.delete_prefix(${literal(bucketId)}, ${literal(prefix)});
`
return sql
}
}