Files

23 lines
2.9 KiB
Plaintext

# What the parser guard accepts and refuses
ACCEPT SELECT count(*) FROM orders WHERE status = 'paid'
ACCEPT SELECT c.country, count(*) FROM customers c JOIN orders o ON o.customer_id = c.id GROUP BY c.country ORDE...
ACCEPT WITH big AS (SELECT order_id FROM order_items GROUP BY order_id HAVING sum(quantity) > 5) SELECT count(*)...
ACCEPT SELECT * FROM orders WHERE id IN (SELECT order_id FROM order_items WHERE quantity > 2)
ACCEPT SELECT 1 /* ; DROP TABLE orders */
ACCEPT SELECT name FROM public.customers
REFUSE DELETE FROM orders (only SELECT is allowed, found Delete)
REFUSE SELECT * FROM orders; DROP TABLE orders (more than one statement (2))
REFUSE SELECT * FROM api_keys (table api_keys is not allowed)
REFUSE SELECT usename FROM pg_user (table pg_user is not allowed)
REFUSE SELECT pg_sleep(3) (function pg_sleep is not allowed)
REFUSE SELECT pg_read_file('/etc/passwd') (function pg_read_file is not allowed)
REFUSE WITH d AS (DELETE FROM orders RETURNING *) SELECT count(*) FROM d (WITH item is not a SELECT (data-modifying CTE))
REFUSE SELECT * FROM orders FOR UPDATE (row locking clause (UPDATE))
REFUSE SELECT * INTO newtab FROM orders (SELECT INTO creates a table)
REFUSE SELECT count(*) FROM generate_series(1, 2000000000) (function generate_series is not allowed)
REFUSE SELECT set_config('default_transaction_read_only', 'off', false) (function set_config is not allowed)
REFUSE SELECT * FROM orders o, "api_keys" k (table "api_keys" is not allowed)
REFUSE SELECT date_part('month', ordered_at) FROM orders (function date_part is not allowed)
REFUSE SELECT now() (function now is not allowed)