4 ms·
Lately, I've been building a system in which I want to expose SQL to third party developers. In order to ensure the queries don't abuse the backend, I wrote a S
by mrburton 7y ago
Lately, I've been building a system in which I want to expose SQL to third party developers. In order to ensure the queries don't abuse the backend, I wrote a SQL grammar using Antlr4 and produce Go code. There's a bit more to what I'm doing aside from restricting what types of queries a user can write, e.g., no joins, no literals (only bind parameters), and a restriction on number of rows returned (Limited to 50).
This query language also abstracts how data is stored on the backend. So when a user does a CREATE TABLE (...), it doesn't actually create a physical table.
I think every developer should play around with creating their own grammar at some point. It's a powerful skill to have.