CodeSampleX

サンプル

drizzle-orm 0.45.2: Escape embedded quotes in SQL identifiers and aliases across dialects in drizzle-orm to prevent syntax errors and injection breakout

検証済みサンプル — npm drizzle-orm 0.45.2: Escape embedded quotes in SQL identifiers and aliases across dialects in drizzle-orm to prevent syntax errors and…

sha256:57a6e36e26613c9d14c388a78043dcbcf145549d1919e796bc8c418b19542a17

このネットワークが提供するのは一つだけです。ビルドされるサンプル。サンドボックスで実行し、署名済みの受領証を保管します。等級はつけず、何も保証しません — 同じコードがあなたの環境でビルドされるかは測定していません。 合格した契約受領証を提出した異なる署名鍵の数です。1 なら作者だけ、2 以上なら他の誰かもビルドしています。鍵は自己生成で背後に登録された身元がないため、数えているのは人ではなく鍵です。 MIT-0

実行証拠

宣言された環境と署名済みの実行を分けてあります。このサンプルが何をどこで実行したかをそのまま確認できます。

証拠の基準
署名済みコントラクト合格
検証レシート
2
ビルドした署名鍵
2
宣言された環境 node linux x64 node node npm

検証実行環境

環境 コントラクト ステージ 実行日
node 22 · linux alpine/x64 · docker ed25519:d91480838ac982c9 PASS compile:SKIPPED · contract:PASS · load:PASS · resolve:PASS
CONTAINER_RUN · node-typescript@1
2026-08-16
node 22 · linux alpine/x64 · docker ed25519:2175b912ea1c23b1 PASS compile:SKIPPED · contract:PASS · load:PASS · resolve:PASS
CONTAINER_RUN · node-typescript@1
2026-08-18

ケース

HOW
ゴール
Escape embedded quotes in SQL identifiers and aliases across dialects in drizzle-orm to prevent syntax errors and injection breakout
パッケージ
シンボル
  • SQLiteSyncDialect.escapeName
  • PgDialect.escapeName
  • MySqlDialect.escapeName
  • SingleStoreDialect.escapeName
  • sql.identifier
  • node:sqlite.DatabaseSync
  • sqliteTable
環境
node
作成日
2026-08-16T06:23:42Z

コントラクト

  1. assert drizzle-orm version is 0.45.2
  2. assert SQLiteSyncDialect.escapeName doubles embedded double-quotes as "" instead of leaving raw quotes unescaped
  3. assert PgDialect.escapeName doubles embedded double-quotes as "" instead of leaving raw quotes unescaped
  4. assert MySqlDialect.escapeName doubles embedded backticks as `` instead of leaving raw backticks unescaped
  5. assert SingleStoreDialect.escapeName doubles embedded backticks as `` instead of leaving raw backticks unescaped
  6. assert compiling sql.identifier with embedded quotes through SQLiteSyncDialect and PgDialect escapes quotes as ""
  7. assert compiling an aliased selection with embedded quotes via .as() routes through escapeName and produces doubled quotes
  8. assert executing a query with an escaped double-quoted identifier against in-memory node:sqlite succeeds and yields the exact unescaped column key
  9. assert an injection breakout payload inside sql.identifier remains safely enclosed in a single identifier without creating injected columns

ファイル

  • NOTES.md
  • csx.json
  • package-lock.json
  • package.json
  • test/contract.mjs

ソースアーティファクトをダウンロード (tar.gz)

オリジンシーダー

csx-seed