Skip to content

fix: make SQL literal generation dialect-safe - #59

Merged
flyxl merged 1 commit into
mainfrom
fix/dialect-safe-sql-literals
Oct 10, 2026
Merged

flyxl merged 1 commit into
mainfrom
fix/dialect-safe-sql-literals

Conversation

@flyxl

@flyxl flyxl commented Oct 10, 2026

Copy link
Copy Markdown
Owner

Summary

  • Replace interpolated row UPDATE/DELETE writes with bound statements for drivers that support parameterized writes. Build the full batch before opening a transaction, and keep values out of preview SQL.
  • Add explicit SQL literal dialects and fail-closed formatting for filters and SQL exports. Migrate internal SQL text call sites away from the legacy generic formatter.
  • Declare dialect support for the SQL drivers, update architecture docs, and add escaping and SQLite round-trip coverage.
  • Report incomplete SQL-file generation without trying to publish or hash a partial artifact.

Validation

  • cargo test -p datazen-driver-api --lib — 334 passed
  • cargo test -p datazen-data-transfer — 224 passed
  • Host row-edit, query-filter, and export tests — 17 + 16 + 16 passed
  • Driver matrix cargo check for MySQL, PostgreSQL, SQLite, SQL Server, DuckDB, ClickHouse, rqlite, Turso, and data-transfer — passed
  • Host cargo check through with-driver-inject — passed
  • SQLite literal and bound UPDATE round-trip — passed
  • PostgreSQL/MySQL shared contract targets compile; PostgreSQL wrapper-classification and sensitivity checks — passed
  • cargo fmt --all and git diff --check — passed

@flyxl
flyxl merged commit a6c7507 into main Oct 10, 2026
3 checks passed
@flyxl
flyxl deleted the fix/dialect-safe-sql-literals branch October 10, 2026 09:08
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant