mirror of
https://github.com/supabase/supabase.git
synced 2026-10-10 20:05:06 +03:00
## Summary - Converts ~27 `executeSql` call sites in `apps/studio/data/**` to build SQL through `safeSql` / `ident` / `literal` / `keyword` / `joinSqlFragments` instead of raw template-string interpolation. - Tightens the `useDatabaseCronJobCreateMutation` and `useDatabaseEventTriggerCreateMutation` `sql`/`query` parameter types from `string` to `SafeSqlFragment` (callers already produce one). - Updates `getDeleteEnumeratedTypeSQL` in `packages/pg-meta` to return `SafeSqlFragment`. - Fixes a bug noticed while testing where Queues integration does not correctly handle queues with uppercase names. ## Pages to manually test - Integrations > Cron Jobs - Integrations > Queues - Database > Triggers > Event Triggers - Database > Indexes - Reports > Query Performance - Storage <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit ## Release Notes * **Bug Fixes** * Queue lookups now correctly handle case-insensitive queue names. * Queue table references are now properly managed and consistently applied throughout the queue management interface. * Improved queue name display normalization in the user interface. * **Chores** * Enhanced SQL query safety across the database layer through parameterized query construction and safer templating approaches. <!-- end of auto-generated comment: release notes by coderabbit.ai -->
61 lines
1.9 KiB
TypeScript
61 lines
1.9 KiB
TypeScript
import { safeSql } from '@supabase/pg-meta/src/pg-format'
|
|
import { useQuery } from '@tanstack/react-query'
|
|
|
|
import { executeSql, ExecuteSqlError } from '../sql/execute-sql-query'
|
|
import { tableKeys } from './keys'
|
|
import type { UseCustomQueryOptions } from '@/types'
|
|
|
|
export type TableName = {
|
|
id: number
|
|
schema: string
|
|
name: string
|
|
}
|
|
|
|
export type TableNamesVariables = {
|
|
projectRef?: string
|
|
connectionString?: string | null
|
|
}
|
|
|
|
const TABLE_NAMES_SQL = safeSql`
|
|
select
|
|
c.oid::int8 as id,
|
|
nc.nspname as schema,
|
|
c.relname as name
|
|
from pg_namespace nc
|
|
join pg_class c on nc.oid = c.relnamespace
|
|
where c.relkind in ('r', 'p')
|
|
and not pg_is_other_temp_schema(nc.oid)
|
|
and nc.nspname not in ('information_schema', 'pg_catalog', 'pg_toast')
|
|
and (
|
|
pg_has_role(c.relowner, 'USAGE')
|
|
or has_table_privilege(c.oid, 'SELECT, INSERT, UPDATE, DELETE, TRUNCATE, REFERENCES, TRIGGER')
|
|
or has_any_column_privilege(c.oid, 'SELECT, INSERT, UPDATE, REFERENCES')
|
|
)
|
|
order by nc.nspname, c.relname
|
|
`
|
|
|
|
export async function getTableNames(
|
|
{ projectRef, connectionString }: TableNamesVariables,
|
|
signal?: AbortSignal
|
|
) {
|
|
const { result } = await executeSql<TableName[]>(
|
|
{ projectRef, connectionString, sql: TABLE_NAMES_SQL, queryKey: ['table-names'] },
|
|
signal
|
|
)
|
|
return result
|
|
}
|
|
|
|
export type TableNamesData = Awaited<ReturnType<typeof getTableNames>>
|
|
export type TableNamesError = ExecuteSqlError
|
|
|
|
export const useTableNamesQuery = <TData = TableNamesData>(
|
|
{ projectRef, connectionString }: TableNamesVariables,
|
|
{ enabled = true, ...options }: UseCustomQueryOptions<TableNamesData, TableNamesError, TData> = {}
|
|
) =>
|
|
useQuery<TableNamesData, TableNamesError, TData>({
|
|
queryKey: tableKeys.names(projectRef),
|
|
queryFn: ({ signal }) => getTableNames({ projectRef, connectionString }, signal),
|
|
enabled: enabled && typeof projectRef !== 'undefined',
|
|
...options,
|
|
})
|