Skip to content

Commit e9f56b8

Browse files
carderneTrigger.dev RepoOps
authored andcommitted
fix(tsql): reject placeholder table expressions
Reject placeholder expressions in table positions so queries use validated table schemas and receive their enforced filters. Mono-RevId: a41f4ec6cac574404da5bc2eb319185b6bdf571d
1 parent 491993f commit e9f56b8

2 files changed

Lines changed: 13 additions & 2 deletions

File tree

‎internal-packages/tsql/src/query/printer.ts‎

Lines changed: 1 addition & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1813,8 +1813,7 @@ export class ClickHousePrinter {
18131813
// Subquery
18141814
joinStrings.push(this.visit(tableExpr));
18151815
} else if ((tableExpr as Placeholder).expression_type === "placeholder") {
1816-
// Placeholder - visit inner expression
1817-
joinStrings.push(this.visit(tableExpr));
1816+
throw new QueryError("Placeholder table expressions are not supported");
18181817
} else {
18191818
throw new QueryError(
18201819
`Unsupported table expression type: ${(tableExpr as Expression).expression_type}`

‎internal-packages/tsql/src/query/security.test.ts‎

Lines changed: 12 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -233,6 +233,18 @@ describe("Cross-Tenant Security", () => {
233233
compile("SELECT * FROM other_database.task_runs");
234234
}).toThrow();
235235
});
236+
237+
it.each([
238+
["direct table", "SELECT * FROM {trigger_dev.task_runs_v2}"],
239+
["joined table", "SELECT * FROM task_runs JOIN {trigger_dev.task_events_v2} ON 1 = 1"],
240+
[
241+
"subquery",
242+
"SELECT id FROM task_runs WHERE id IN (SELECT id FROM {trigger_dev.task_runs_v2})",
243+
],
244+
["CTE", "WITH raw_runs AS (SELECT * FROM {trigger_dev.task_runs_v2}) SELECT * FROM raw_runs"],
245+
])("should reject placeholder table expressions in a %s", (_, query) => {
246+
expect(() => compile(query)).toThrowError("Placeholder table expressions are not supported");
247+
});
236248
});
237249
});
238250

0 commit comments

Comments
 (0)