7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
|
# File 'app/controllers/concerns/sql_genius/query_execution.rb', line 7
def execute
sql = params[:sql].to_s.strip
row_limit = if params[:row_limit].present?
params[:row_limit].to_i.clamp(1, sql_genius_config.max_row_limit)
else
sql_genius_config.default_row_limit
end
runner_config = SqlGenius::Core::QueryRunner::Config.new(
blocked_tables: sql_genius_config.blocked_tables,
masked_column_patterns: sql_genius_config.masked_column_patterns,
query_timeout_ms: sql_genius_config.query_timeout_ms,
)
runner = SqlGenius::Core::QueryRunner.new(rails_connection, runner_config)
begin
result = runner.run(sql, row_limit: row_limit)
rescue SqlGenius::Core::QueryRunner::Rejected => e
audit(:rejection, sql: sql, reason: e.message)
return render(json: { error: e.message }, status: :unprocessable_entity)
rescue SqlGenius::Core::QueryRunner::Timeout
audit(:error, sql: sql, error: "Query timeout")
return render(json: { error: "Query exceeded the #{sql_genius_config.query_timeout_ms / 1000} second timeout limit.", timeout: true }, status: :unprocessable_entity)
rescue ActiveRecord::StatementInvalid => e
audit(:error, sql: sql, error: e.message)
return render(json: { error: "Query error: #{e.message.split(":").last.strip}" }, status: :unprocessable_entity)
end
audit(:query, sql: sql, execution_time_ms: result.execution_time_ms, row_count: result.row_count)
render(json: {
columns: result.columns,
rows: result.rows,
row_count: result.row_count,
execution_time_ms: result.execution_time_ms,
truncated: result.truncated,
})
end
|