Skip to content

Prevent SQL injection in FlameDB queries - #153

Open
gmunoz wants to merge 1 commit into
masterfrom
fix-flamedb-query-strings
Open

gmunoz wants to merge 1 commit into
masterfrom
fix-flamedb-query-strings

Conversation

@gmunoz

@gmunoz gmunoz commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

Parameterize request and RQL filter values passed to ClickHouse instead of interpolating them into SQL strings. Allowlist dynamic query fields and use QueryContext for query execution.

Fixes #152

Parameterize request and RQL filter values passed to ClickHouse instead
of interpolating them into SQL strings. Allowlist dynamic query fields
and use QueryContext for query execution.

Fixes #152
@gmunoz
gmunoz requested a review from lennin-cp October 1, 2026 23:26
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

FlameDB: ClickHouse queries not properly interpolating query strings

1 participant