hutiefang76 opened a new issue, #12502:
URL: https://github.com/apache/seatunnel/issues/12502

   ### What happened
   
   DuckDB catalog metadata lookups interpolate the schema and table names 
directly into SQL string literals. Valid DuckDB names containing an apostrophe, 
such as `odd'schema` or `odd'table`, produce malformed SQL in both 
`getTableWithConditionSql` and `getSelectColumnsSql`. An untrusted name can 
also alter the metadata query expression.
   
   ### Expected behavior
   
   Catalog table existence and column metadata lookup should treat schema and 
table names as literal values, including apostrophes, without changing the 
query structure.
   
   ### Reproduction
   
   Create schema `"odd'schema"` and table `"odd'schema"."odd'table" (id 
INTEGER)` with DuckDB JDBC, then call `DuckDBCatalog.tableExists` or `getTable` 
with the matching `TablePath`. The current catalog query fails with a DuckDB 
parser error near `schema`.
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to