DarkAssassinator opened a new issue, #12393:
URL: https://github.com/apache/dolphinscheduler/issues/12393

   ### Search before asking
   
   - [X] I had searched in the 
[issues](https://github.com/apache/dolphinscheduler/issues?q=is%3Aissue) and 
found no similar feature requirement.
   
   
   ### Description
   
   In answering community questions and during community discussions, I found 
that many people need to use `table names` as variables. But now ds do not 
support it. Because we cannot pass tables as bind variable using prepared 
statement
   So I suggest that we can add a `TableName` parmeter, just for SQL task 
plugin. 
   > ❓: **_How to Avoid SQL Injection Attacks_**
   > We can verify the value of the `TableName` parameter, and we must ensure 
that the table does exist in the database schema.
   
   + Old same issue has been closed : 
https://github.com/apache/dolphinscheduler/issues/11566, but i think that ds 
need add this feature.
   
   
![image](https://user-images.githubusercontent.com/20518339/196041993-441dce5d-aaff-4044-becb-05dff1ebfeac.png)
   
   
   ### Use case
   
   User can add `TableName` parameter.
   
   ### Related issues
   
   _No response_
   
   ### Are you willing to submit a PR?
   
   - [X] Yes I am willing to submit a PR!
   
   ### Code of Conduct
   
   - [X] I agree to follow this project's [Code of 
Conduct](https://www.apache.org/foundation/policies/conduct)
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: 
[email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to