Skip to content

Avoid possible SQL injection by refactoring string-based query construction #34252

Description

@hussein-awala

Body

Some of our queries are string based, and they are passed directly to sqlalchemy session.execute(). To avoid SQL injection, we can profit from sqlalchemy by rewriting the queries bind parameters syntax or the select API.

  • Airflow Core - migration
  • Airflow Core - utils
  • Airflow Providers - Amazon
  • Airflow Providers - Apache.Cassandra
  • Airflow Providers - Apache.Hive
  • Airflow Providers - common.sql
  • Airflow Providers - Databricks
  • Airflow Providers - Google
  • Airflow Providers - MySQL
  • Airflow Providers - Oracle
  • Airflow Providers - Postgres
  • Airflow Providers - SalesForce

Committer

  • I acknowledge that I am a maintainer/committer of the Apache Airflow project.

Metadata

Metadata

Assignees

Labels

kind:metaHigh-level information important to the community

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions