Add CH.sql templates inside expressions, and Db.sql join/raw/empty - #17
Merged
Merged
Conversation
CH.sql(type)`...` is a typed expression, CH.sql`...` an untyped one and CH.sql.cond`...` a condition, usable anywhere the builder takes one: select, where, ON, an UPDATE's SET. Interpolated columns, expressions and nested templates render as SQL; params stay placeholders (bound on Postgres); a builder query becomes a subquery compiled with the outer query, its tenant scope counted; a plain value becomes the dialect's escaped literal. Arrays and objects have no literal without their SQL type, so they fail the compile and point at param.of. sql.ident quotes plain names, sql.raw splices text, sql.join renders and joins values. Db.sql gains join (one bound value per item), raw and empty. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
|
Warning Review limit reachedYou've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. Next included review available in 14 minutes. View limit detailsLimit details: You’ve used the included review currently available. Review configuration: ⚙️ Run configuration
📒 Files selected for processing (12)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
From review: - A template condition was spliced bare, so CH.sql.cond`a OR b` in a where list became `a OR b AND org = $1`, reading every tenant while the query still reported single-tenant. Templates now render in parentheses (expressions too); sql.join stays bare to fit IN (...). - sql.raw / sql.ident, and Db.sql's templates, identifiers and raw text, were recognised by a string _tag, which an object parsed from request JSON could forge to splice SQL (pre-existing for Db.sql templates). They are now recognised by identity through a private WeakSet; a forged object is a value: bound on Postgres, an escaped literal or an error on ClickHouse. - A negative number after `-` wrote `10--1`, commenting out the rest of the line; negatives, and params ClickHouse inlines, are parenthesized. - An empty sql.join / Db.sql.join fails instead of writing `IN ()`; an invalid Date is a typed failure; DateTime is detected with DateTime.isDateTime; a unionAll gets a message pointing at fromUnion. - Stop tracking the node_modules symlink the worktree committed, and ignore node_modules whether it is a directory or a link. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
From the follow-up review: Db.sql`SELECT 10-${-1}` wrote `10--1` on
ClickHouse, which inlines values, commenting out the rest of the line.
Postgres binds values, so it was unaffected.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The
sqlitem fromdesign/gap-review.md(Maple has ~163sqluses). Stacked on #16.What changes
CH.sql(type)gives a typedExpr(it decodes when selected),CH.sql`…`an untyped one (costs the row schema, likeuntypedExpr), andCH.sql.condaCondition. They work in select, where, ON, and an UPDATE's SET.param.*stays a placeholder, bound on Postgres.Date,DateTime.Utcornullbecomes the dialect's escaped literal.param.of.sql.identquotes plain names,sql.rawsplices text you control, andsql.joinrenders and joins values.Db.sqlgainsjoin(one bound value per item),rawandempty.A deliberate limit
A plain value inside
CH.sqlis an escaped literal, not a bound parameter. That matches how the builder treats values everywhere else; params are what bind. Values and params can't leak into SQL either way.Testing
bun run typecheckandbun run test: 558 unit tests and the doc checks pass. The live ClickHouse suite passes on 26.2 and 26.8.src/ch/sql-template.test.tscovers both dialects, params, raw/ident/join, subquery tenant scope, every failure, and use in UPDATE.@>filter with a bound param,->>and a typedxidcast. NewDb.sqlrender tests.🤖 Generated with Claude Code
Need help on this PR? Tag
@codesmith-botwith what you need. Autofix is disabled.