Moebius.Identifier (Moebius v5.0.0)

Copy Markdown View Source

Checks the table, column and function names Moebius puts into SQL.

Values always travel as $n parameters, but Postgres can't take a name as a parameter, so names are written into the SQL text. Every name is checked first, and anything that isn't a plain name raises ArgumentError before any SQL is built.

A plain name is letters, digits, _ and $, starting with a letter or _, optionally qualified by a schema (membership.users). A double-quoted name ("Order Items") is accepted too, as long as it contains no quote.

Strings you pass as SQL fragments (filter("price > $1", 10), select("count(*) as n")) are your own SQL and are used as written. Only pass trusted text there.

Summary

Functions

Returns the sort direction as SQL, or raises ArgumentError.

Quotes a JSON key as a SQL string literal, for body -> 'key'. Single quotes are doubled. A backslash raises ArgumentError: with standard_conforming_strings off (a legacy server setting) it would escape the closing quote, so it is never written into SQL.

Returns the name as a string, or raises ArgumentError.

Checks every name in a list and joins them with ,.

Checks a SQL file name: letters, digits, _, -, and / between folders. No ...

Functions

direction!(dir)

Returns the sort direction as SQL, or raises ArgumentError.

json_key(key)

Quotes a JSON key as a SQL string literal, for body -> 'key'. Single quotes are doubled. A backslash raises ArgumentError: with standard_conforming_strings off (a legacy server setting) it would escape the closing quote, so it is never written into SQL.

iex> Moebius.Identifier.json_key(:email)
"'email'"
iex> Moebius.Identifier.json_key("o'brien")
"'o''brien'"

name!(name)

Returns the name as a string, or raises ArgumentError.

iex> Moebius.Identifier.name!(:users)
"users"
iex> Moebius.Identifier.name!("membership.users")
"membership.users"
iex> Moebius.Identifier.name!("users; drop table users")
** (ArgumentError) invalid SQL identifier: "users; drop table users"

names!(names)

Checks every name in a list and joins them with ,.

script!(name)

Checks a SQL file name: letters, digits, _, -, and / between folders. No ...