Implemented API support for set_limit (sqlite3_limit) in sqlite#4975
Open
LucaCappelletti94 wants to merge 1 commit intodiesel-rs:mainfrom
Open
Implemented API support for set_limit (sqlite3_limit) in sqlite#4975LucaCappelletti94 wants to merge 1 commit intodiesel-rs:mainfrom
set_limit (sqlite3_limit) in sqlite#4975LucaCappelletti94 wants to merge 1 commit intodiesel-rs:mainfrom
Conversation
Contributor
Author
|
The compile test failures ( I will do a quick separate PR to fix them later if that is correct and they are unrelated to this PR. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR exposes SQLite's
sqlite3_limitAPI through new methods onSqliteConnection. It is another PR in the series of: "let's make more of SQLite usable with Diesel in frontend WASM development", but it really applies to many other cases.Motivation
SQLite's security documentation explicitly recommends using
sqlite3_limit()for hardening:The documentation also notes: "Most applications can reduce limits dramatically without impacting functionality."
SQLite's limits documentation provides specific context:
CompoundSelect: Defaults to 500, but "in practice we almost never see the number of terms in a compound select exceed single digits"ExprDepth: Can prevent stack exhaustion from deeply nested expressionsSqlLength: The security page suggests reducing from 1,000,000,000 to 100,000 for high-security deploymentsWhile users could technically call the FFI directly, this PR provides a safe, ergonomic, and documented API that makes following SQLite's security recommendations straightforward.
Usage
Apply all recommended security limits in one call:
Or configure individual limits: