SEZ9 commented on issue #12502:
URL: https://github.com/apache/seatunnel/issues/12502#issuecomment-5863161598

   Thanks for the clear report and reproduction. Could you share the SeaTunnel 
version/commit you tested against, along with the exact DuckDB parser error 
message, so we can confirm the affected code paths?
   
   The proposed fix direction sounds right: build the metadata queries in 
getTableWithConditionSql and getSelectColumnsSql with PreparedStatement 
parameters (or at minimum escape single quotes by doubling them) rather than 
concatenating the schema/table names as string literals. A PR is welcome if 
you'd like to take it.
   
   Please also add a unit/integration test covering identifiers with 
apostrophes (e.g. "odd'schema"."odd'table") for tableExists, getTable, and 
column metadata lookup, and check whether other JDBC-based catalogs share the 
same string-interpolation pattern.
   
   <!-- streview-comment:1378 -->


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to