Skip to content

fix(redshift): escape SQL identifiers and literals in metadata/DDL paths (#1914) - #2203

Open
HandSonic wants to merge 4 commits into
OtterMind:mainfrom
HandSonic:fix/sqli2-redshift
Open

fix(redshift): escape SQL identifiers and literals in metadata/DDL paths (#1914)#2203
HandSonic wants to merge 4 commits into
OtterMind:mainfrom
HandSonic:fix/sqli2-redshift

Conversation

@HandSonic

Copy link
Copy Markdown
Contributor

Part of the SQL-injection hardening tracked in #1914. Prior art: #2052 (Oracle), #2053 (SQL Server), and the wave-1 batch (#2172-#2177).

These are second-order injection paths: values such as table/schema/view/index names originate from the connected database's own metadata, so exploitation requires a maliciously named object in a target database.

What changed (2 sites)

RedshiftMetaData tableDDL/viewDDL identifier paths now quoted+escaped via new RedshiftSqlEscapes.

Verification

mvn -B -pl chat2db-community-plugins/chat2db-community-redshift -f chat2db-community-server/pom.xml -Dmaven.test.skip=false -DskipTests=false -Dsurefire.includes=**/*Test.java -Dsurefire.failIfNoSpecifiedTests=false -Dmaven.test.failure.ignore=false test

Result: Tests run: 9, Failures: 0, Errors: 0, Skipped: 0.

This branch also passed a two-lens adversarial review (escape-correctness/coverage + regression/test-efficacy); all blocking findings were fixed and re-tested before submission.

…r maintainer review (OtterMind#1914)

- new RedshiftIdentifierProcessor (SPI ISQLIdentifierProcessor): quoteIdentifier
  with double-quote doubling, escapeString with single-quote doubling
- RedshiftMetaData overrides getSQLIdentifierProcessor(); SHOW CREATE TABLE
  call site uses RedshiftIdentifierProcessor.INSTANCE
- RedshiftSqlEscapes removed; tests migrated (9 green)
…uote for DDL paths (OtterMind#1914)

- quoteIdentifier(String) is conditional again: null/blank passthrough,
  valid plain identifiers returned unquoted, otherwise wrapped with
  double quotes after stripping one pair and doubling embedded quotes
- new quoteIdentifierAlways(String) for DDL-generation sites;
  buildShowCreateTableSql uses it (was RedshiftSqlEscapes.quoteIdentifier)
- quoteIdentifierIgnoreCase keeps the always-quote SPI variant meaning;
  versioned overload delegates to quoteIdentifier(String)
- tests cover both conditional and always behaviors incl. null passthrough
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Status: In Review

Development

Successfully merging this pull request may close these issues.

2 participants