|
| 1 | +import datetime |
| 2 | +import re |
| 3 | + |
| 4 | +import sqlalchemy |
| 5 | +import sqlparse |
| 6 | + |
| 7 | + |
| 8 | +class SQLSanitizer: |
| 9 | + """Sanitizes SQL values. |
| 10 | + """ |
| 11 | + |
| 12 | + def __init__(self, dialect): |
| 13 | + self._dialect = dialect |
| 14 | + |
| 15 | + def escape(self, value): |
| 16 | + """Escapes value using engine's conversion function. |
| 17 | + https://docs.sqlalchemy.org/en/latest/core/type_api.html#sqlalchemy.types.TypeEngine.literal_processor |
| 18 | +
|
| 19 | + :param value: The value to be sanitized |
| 20 | +
|
| 21 | + :returns: The sanitized value |
| 22 | + """ |
| 23 | + # pylint: disable=too-many-return-statements |
| 24 | + if isinstance(value, (list, tuple)): |
| 25 | + return self.escape_iterable(value) |
| 26 | + |
| 27 | + if isinstance(value, bool): |
| 28 | + return sqlparse.sql.Token( |
| 29 | + sqlparse.tokens.Number, |
| 30 | + sqlalchemy.types.Boolean().literal_processor(self._dialect)(value)) |
| 31 | + |
| 32 | + if isinstance(value, bytes): |
| 33 | + if self._dialect.name in {"mysql", "sqlite"}: |
| 34 | + # https://dev.mysql.com/doc/refman/8.0/en/hexadecimal-literals.html |
| 35 | + return sqlparse.sql.Token(sqlparse.tokens.Other, f"x'{value.hex()}'") |
| 36 | + if self._dialect.name in {"postgres", "postgresql"}: |
| 37 | + # https://dba.stackexchange.com/a/203359 |
| 38 | + return sqlparse.sql.Token(sqlparse.tokens.Other, f"'\\x{value.hex()}'") |
| 39 | + |
| 40 | + raise RuntimeError(f"unsupported value: {value}") |
| 41 | + |
| 42 | + string_processor = sqlalchemy.types.String().literal_processor(self._dialect) |
| 43 | + if isinstance(value, datetime.date): |
| 44 | + return sqlparse.sql.Token( |
| 45 | + sqlparse.tokens.String, string_processor(value.strftime("%Y-%m-%d"))) |
| 46 | + |
| 47 | + if isinstance(value, datetime.datetime): |
| 48 | + return sqlparse.sql.Token( |
| 49 | + sqlparse.tokens.String, string_processor(value.strftime("%Y-%m-%d %H:%M:%S"))) |
| 50 | + |
| 51 | + if isinstance(value, datetime.time): |
| 52 | + return sqlparse.sql.Token( |
| 53 | + sqlparse.tokens.String, string_processor(value.strftime("%H:%M:%S"))) |
| 54 | + |
| 55 | + if isinstance(value, float): |
| 56 | + return sqlparse.sql.Token( |
| 57 | + sqlparse.tokens.Number, |
| 58 | + sqlalchemy.types.Float().literal_processor(self._dialect)(value)) |
| 59 | + |
| 60 | + if isinstance(value, int): |
| 61 | + return sqlparse.sql.Token( |
| 62 | + sqlparse.tokens.Number, |
| 63 | + sqlalchemy.types.Integer().literal_processor(self._dialect)(value)) |
| 64 | + |
| 65 | + if isinstance(value, str): |
| 66 | + return sqlparse.sql.Token(sqlparse.tokens.String, string_processor(value)) |
| 67 | + |
| 68 | + if value is None: |
| 69 | + return sqlparse.sql.Token( |
| 70 | + sqlparse.tokens.Keyword, |
| 71 | + sqlalchemy.types.NullType().literal_processor(self._dialect)(value)) |
| 72 | + |
| 73 | + raise RuntimeError(f"unsupported value: {value}") |
| 74 | + |
| 75 | + def escape_iterable(self, iterable): |
| 76 | + """Escapes each value in iterable and joins all the escaped values with ", ", formatted for |
| 77 | + SQL's ``IN`` operator. |
| 78 | +
|
| 79 | + :param: An iterable of values to be escaped |
| 80 | +
|
| 81 | + :returns: A comma-separated list of escaped values from ``iterable`` |
| 82 | + :rtype: :class:`sqlparse.sql.TokenList` |
| 83 | + """ |
| 84 | + |
| 85 | + return sqlparse.sql.TokenList( |
| 86 | + sqlparse.parse(", ".join([str(self.escape(v)) for v in iterable]))) |
| 87 | + |
| 88 | + |
| 89 | +def escape_verbatim_colon(value): |
| 90 | + """Escapes verbatim colon from a value so as it is not confused with a parameter marker. |
| 91 | + """ |
| 92 | + |
| 93 | + # E.g., ':foo, ":foo, :foo will be replaced with |
| 94 | + # '\:foo, "\:foo, \:foo respectively |
| 95 | + return re.sub(r"(^(?:'|\")|\s+):", r"\1\:", value) |
0 commit comments