sadpandajoe commented on code in PR #41803:
URL: https://github.com/apache/superset/pull/41803#discussion_r3835832530


##########
superset/sql/dialects/trino.py:
##########
@@ -0,0 +1,469 @@
+# Licensed to the Apache Software Foundation (ASF) under one
+# or more contributor license agreements.  See the NOTICE file
+# distributed with this work for additional information
+# regarding copyright ownership.  The ASF licenses this file
+# to you under the Apache License, Version 2.0 (the
+# "License"); you may not use this file except in compliance
+# with the License.  You may obtain a copy of the License at
+#
+#   http://www.apache.org/licenses/LICENSE-2.0
+#
+# Unless required by applicable law or agreed to in writing,
+# software distributed under the License is distributed on an
+# "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
+# KIND, either express or implied.  See the License for the
+# specific language governing permissions and limitations
+# under the License.
+
+from __future__ import annotations
+
+import typing as t
+
+from sqlglot import exp
+from sqlglot.dialects.trino import Trino as SqlglotTrino
+from sqlglot.tokens import Token, TokenType
+
+# Keywords that open a block terminated by ``END`` in Trino SQL routines
+# (https://trino.io/docs/current/udf/sql.html). ``CASE`` is included because
+# both the ``CASE`` statement and the ``CASE`` expression are terminated by
+# ``END``, so counting them keeps the depth balanced either way.
+BLOCK_OPENERS: set[str] = {"BEGIN", "CASE", "IF", "LOOP", "REPEAT", "WHILE"}
+
+# Keywords that are also scalar functions in Trino (e.g. ``IF(a, b, c)`` and
+# ``REPEAT('a', 3)``). When immediately followed by ``(`` they are function
+# calls, not block openers, unless the token stream shows otherwise (see
+# ``_is_paren_condition_block``).
+AMBIGUOUS_OPENERS: set[str] = {"IF", "REPEAT"}
+
+BODY_KEYWORDS: tuple[str, str] = ("RETURN", "BEGIN")
+
+# ``BEGIN``, ``CASE``, and ``END`` are reserved words in sqlglot's Trino
+# tokenizer, so they always carry one of these dedicated token types when
+# used as keywords, and a different one (``STRING``/``IDENTIFIER``) when
+# used as a string literal or quoted identifier, e.g. the string ``'END'``
+# or the quoted identifier ``"end"``. ``IF``, ``LOOP``, ``REPEAT``, and
+# ``WHILE`` are not reserved, so the tokenizer emits ``VAR`` for them both
+# when they're used as a keyword and when they're an unquoted identifier;
+# requiring ``VAR`` still rules out string literals and quoted identifiers,
+# which is the ambiguity ``_is_keyword_token`` guards against.
+_RESERVED_BLOCK_TOKEN_TYPES: dict[str, TokenType] = {
+    "BEGIN": TokenType.BEGIN,
+    "CASE": TokenType.CASE,
+    "END": TokenType.END,
+}
+
+# Token text that can immediately precede a new routine statement inside a
+# ``BEGIN ... END`` body: the start of the body itself, a statement
+# separator, a branch/loop keyword that introduces a nested statement list,
+# or ``:`` following a statement label (e.g. ``top: WHILE ... END WHILE``).
+# Used by ``_is_routine_keyword`` to tell a non-reserved block-opening
+# keyword (``IF``, ``LOOP``, ``REPEAT``, ``WHILE``) apart from an unquoted
+# routine parameter or column reference spelled the same way, since Trino
+# does not reserve these words and its tokenizer emits ``VAR`` for both.
+_STATEMENT_START_PREV_TEXTS: frozenset[str] = frozenset(
+    {"BEGIN", ";", "THEN", "ELSE", "DO", "LOOP", "REPEAT", ":"}
+)
+
+
+def _is_keyword_token(token: Token, text: str) -> bool:
+    """
+    Determine whether ``token`` (whose upper-cased text is ``text``) is an
+    actual occurrence of a routine keyword, as opposed to a string literal
+    or quoted identifier that happens to spell the same word.
+    """
+    if (expected := _RESERVED_BLOCK_TOKEN_TYPES.get(text)) is not None:
+        return token.token_type == expected
+    return token.token_type == TokenType.VAR
+
+
+def _is_routine_keyword(token: Token, text: str, prev_text: str) -> bool:
+    """
+    Determine whether ``token`` is an actual occurrence of a routine block
+    keyword, as opposed to a string literal or quoted identifier that
+    happens to spell the same word (see ``_is_keyword_token``), or, for the
+    non-reserved keywords (``IF``, ``LOOP``, ``REPEAT``, ``WHILE``), an
+    unquoted parameter or column reference spelled the same way, e.g. a UDF
+    parameter named ``loop`` in ``RETURN loop``. A block-opening keyword only
+    ever appears where a new statement can start, so ``prev_text`` (the
+    upper-cased text of the immediately preceding token) is checked against
+    ``_STATEMENT_START_PREV_TEXTS`` for these ambiguous, non-reserved words.
+    """
+    if not _is_keyword_token(token, text):
+        return False
+    if text in _RESERVED_BLOCK_TOKEN_TYPES:
+        return True
+    return prev_text in _STATEMENT_START_PREV_TEXTS
+
+
+def _is_paren_condition_block(tokens: t.Sequence[Token], paren_index: int) -> 
bool:
+    """
+    Determine whether the parenthesized group starting at 
``tokens[paren_index]``
+    (an ``L_PAREN``) is a procedural block condition, e.g. ``IF (a > b) THEN``,
+    as opposed to a scalar function call argument list, e.g. ``IF(a, b, c)``.
+
+    Only ``IF`` has this ambiguity: a parenthesized condition is followed by
+    ``THEN``, while a scalar function call's closing paren never is.
+    """
+    depth = 0
+    for i in range(paren_index, len(tokens)):
+        token_type = tokens[i].token_type
+        if token_type == TokenType.L_PAREN:
+            depth += 1
+        elif token_type == TokenType.R_PAREN:
+            depth -= 1
+            if depth == 0:
+                next_token = tokens[i + 1] if i + 1 < len(tokens) else None
+                return (
+                    next_token is not None and next_token.token_type == 
TokenType.THEN
+                )
+    return False
+
+
+def _extract_function_calls(tokens: t.Sequence[Token]) -> list[exp.Anonymous]:
+    """
+    Scan the raw tokens of an inline UDF specification for scalar function
+    calls, e.g. ``regexp_replace(...)`` in ``RETURN regexp_replace(...)``, so
+    that ``SQLScript.check_functions_present`` still sees them even though
+    the UDF body itself is kept as opaque, verbatim text.
+
+    A call is any word-like token immediately followed by ``(``. Most scalar
+    functions tokenize as plain ``VAR`` (Trino's tokenizer does not
+    distinguish an unquoted identifier from an unreserved keyword), but a few
+    (e.g. ``current_user``, ``localtime``) are reserved words with their own
+    dedicated ``TokenType`` and would otherwise slip past a ``VAR``-only
+    check while still being callable with parentheses, so the token text
+    itself (rather than its type) decides whether it looks like a call head.
+    This can also match a routine/parameter type name (e.g. ``varchar(10)``),
+    a keyword used with parenthesized syntax (e.g. ``CAST(...)``, ``IN
+    (...)``), or the UDF's own name at its declaration site; those false
+    positives are harmless here, since this list is only used to check for
+    the presence of specific denylisted function names, not to validate the
+    call itself.
+    """
+    return [
+        exp.Anonymous(this=tokens[i - 1].text)
+        for i in range(1, len(tokens))
+        if tokens[i].token_type == TokenType.L_PAREN
+        and tokens[i - 1].text.isidentifier()

Review Comment:
   This only records names followed by `(`, but Trino permits `current_user` 
without parentheses. That valid form stays hidden from 
`DISALLOWED_SQL_FUNCTIONS` inside the opaque UDF; could we extract or reject it 
too?



-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to