scriptsql

package
v1.138.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 29, 2026 License: Apache-2.0 Imports: 9 Imported by: 0

Documentation

Overview

Package scriptsql binds a managed script's platform.query parameters into its SQL (#1389): each :name placeholder becomes a SQL literal rendered from the value the script passed, and a registered table's record becomes its quoted name (#1948).

Index

Constants

This section is empty.

Variables

This section is empty.

Functions

func Bind

func Bind(sql string, params *starlark.Dict) (string, error)

Bind substitutes :name placeholders in sql with SQL literals rendered from params, and returns the statement to execute.

This exists so a script never has to build SQL by concatenation. An author who writes `"... WHERE region = '" + region + "'"` has written a statement whose meaning depends on the value — the classic mistake, and one an agent authoring under time pressure makes readily. Binding here renders each value according to its own type, with quoting the value cannot escape, so a region named `x' OR '1'='1` is a region name and nothing else.

Substitution is state-aware: a `:name` inside a string literal, inside a quoted identifier, or inside a comment is text, not a placeholder, and `::` is a cast rather than the start of one. Getting that wrong in either direction is a correctness bug (a rewritten literal) or a security bug (an unbound placeholder reaching the engine).

Every placeholder must have a value and every value must be used: an unbound placeholder would reach the query engine as syntax, and an unused value is nearly always a typo in one name or the other.

Types

This section is empty.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL