rusackas commented on code in PR #44546: URL: https://github.com/apache/superset/pull/44546#discussion_r4154915789
########## tests/testcontainers/db_engine_specs/test_bigquery.py: ########## @@ -0,0 +1,152 @@ +# Licensed to the Apache Software Foundation (ASF) under one +# or more contributor license agreements. See the NOTICE file +# distributed with this work for additional information +# regarding copyright ownership. The ASF licenses this file +# to you under the Apache License, Version 2.0 (the +# "License"); you may not use this file except in compliance +# with the License. You may obtain a copy of the License at +# +# http://www.apache.org/licenses/LICENSE-2.0 +# +# Unless required by applicable law or agreed to in writing, +# software distributed under the License is distributed on an +# "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY +# KIND, either express or implied. See the License for the +# specific language governing permissions and limitations +# under the License. +""" +Tests Superset's BigQuery string-literal escaping (superset/db_engine_specs/ +bigquery.py's ``_monkeypatch_bigquery_string_literal``) against a real +GoogleSQL query engine, spun up on demand via testcontainers. Run via +.github/workflows/testcontainers.yml. + +sc-120493-adjacent investigation: an apostrophe in a filter value used to +break BigQuery queries (apache/superset#35857 / #38835, doubled single +quotes -- BigQuery rejects ``'Armando''s'`` as two adjacent string literals +needing whitespace between them). The current fix backslash-escapes instead. +Reasoning about correctness from the ``sqlalchemy-bigquery`` dialect source +and the BigQuery DBAPI's ``pyformat`` paramstyle handling is necessary but +not sufficient; this locks in the actual compiled-and-executed behavior +against a real engine instead. +""" + +from collections.abc import Iterator + +import pytest +import sqlalchemy as sa +from sqlalchemy.engine import Engine + +pytestmark = pytest.mark.testcontainers + +from ._driver import require_driver # noqa: E402 + +require_driver("testcontainers.core.container") + +from google.cloud import bigquery # noqa: E402 +from sqlalchemy_bigquery import BigQueryDialect # noqa: E402 + +# Importing this triggers _monkeypatch_bigquery_string_literal(), exactly as +# it runs in a real Superset process. +import superset.db_engine_specs.bigquery # noqa: E402, F401 + +from ._bigquery_container import BigQueryContainer # noqa: E402 + +DATASET = "ds" +TABLE = "t" + + [email protected](scope="module") +def bq_client() -> Iterator[bigquery.Client]: + with BigQueryContainer() as container: + client = container.get_client() + client.create_dataset(f"{client.project}.{DATASET}") + client.query(f"CREATE TABLE {DATASET}.{TABLE} (name STRING)").result() + yield client + + [email protected](scope="module") +def engine(bq_client) -> Engine: + # user_supplied_client=true is a URL query param, not just a connect_args + # key: parse_url() only sets BigQueryDialect.create_connect_args() to + # accept the connect_args={"client": ...} override when it's present, + # otherwise it tries to build a client from real GCP credentials. + return sa.create_engine( + "bigquery://?user_supplied_client=true", connect_args={"client": bq_client} + ) + + +def _compiled_literal(expr: sa.ColumnElement) -> str: + """Render ``expr`` exactly as Superset's actual code path does: compiled + with ``literal_binds=True``, then executed as a plain string with no + separate bind parameters (superset.db_engine_specs.base.BaseEngineSpec + .execute() calls ``cursor.execute(query)``, nothing else).""" + return str( + expr.compile(dialect=BigQueryDialect(), compile_kwargs={"literal_binds": True}) + ) + + +def _insert_and_find(engine: Engine, value: str) -> list[str]: + t = sa.table(TABLE, sa.column("name")) + with engine.connect() as conn: + conn.execute(sa.text(f"DELETE FROM {DATASET}.{TABLE} WHERE TRUE")) # noqa: S608 + insert_literal = _compiled_literal(sa.literal(value)) + conn.execute( + sa.text( + f"INSERT INTO {DATASET}.{TABLE} (name) VALUES ({insert_literal})" # noqa: S608 + ) + ) + where = _compiled_literal(t.c.name == value) + rows = conn.execute( + sa.text(f"SELECT name FROM {DATASET}.{TABLE} WHERE {where}") # noqa: S608 Review Comment: Good catch. Switched `_insert_and_find` to a raw DBAPI cursor (`engine.raw_connection()` + `cursor.execute()`, no `sa.text()`/`conn.execute()`), so it matches `cursor.execute(query)` exactly. Turns out a literal `%%` in the data does get collapsed to `%` there, `_format_operation`'s unconditional de-escape when there's no `parameters` arg. That's a DBAPI-level thing, not something `literal_processor` can fix, so I pinned it as its own test instead of asserting it survives unchanged. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected] --------------------------------------------------------------------- To unsubscribe, e-mail: [email protected] For additional commands, e-mail: [email protected]
