示例#1
0
    def query(self, query, additional_locals=None, safe_mode=False):
        """Executes the given SQLAlchemy query string.

        Args:
            query: The SQLAlchemy ORM query (or Python code) to be executed.
            additional_locals: Any additional local variables to inject into the execution context
                when executing the query.
            safe_mode: Boolean value indicating whether or not to execute queries in safe mode
                only. If True, this only allows MLAlchemy-style queries. If False, this allows
                both exec() and MLAlchemy-style queries. Default: False.

        Returns:
            The result of executing the query.
        """
        logger.debug("Attempting to execute database query: %s", query)

        if safe_mode and not isinstance(query, dict):
            raise SafetyViolationError(context=self.error_context)

        if isinstance(query, dict):
            logger.debug("Executing query in safe mode (MLAlchemy)")
            return mlalchemy.parse_query(query).to_sqlalchemy(
                self.session, self.tables).all()
        else:
            logger.debug("Executing unsafe query (Python exec())")
            if additional_locals is not None:
                for k, v in additional_locals.items():
                    locals()[k] = v

            exec(compile('result = %s' % query.strip(), '<string>', 'exec'),
                 globals(), locals())
            return locals()['result']
示例#2
0
    def query(self, query, additional_locals=None, safe_mode=False):
        """Executes the given SQLAlchemy query string.

        Args:
            query: The SQLAlchemy ORM query (or Python code) to be executed.
            additional_locals: Any additional local variables to inject into the execution context
                when executing the query.
            safe_mode: Boolean value indicating whether or not to execute queries in safe mode
                only. If True, this only allows MLAlchemy-style queries. If False, this allows
                both exec() and MLAlchemy-style queries. Default: False.

        Returns:
            The result of executing the query.
        """
        logger.debug("Attempting to execute database query: %s", query)

        if safe_mode and not isinstance(query, dict):
            raise SafetyViolationError(
                context=self.error_context
            )

        if isinstance(query, dict):
            logger.debug("Executing query in safe mode (MLAlchemy)")
            return mlalchemy.parse_query(query).to_sqlalchemy(self.session, self.tables).all()
        else:
            logger.debug("Executing unsafe query (Python exec())")
            if additional_locals is not None:
                for k, v in iteritems(additional_locals):
                    locals()[k] = v

            exec(
                compile(
                    'result = %s' % query.strip(),
                    '<string>',
                    'exec'
                ),
                globals(),
                locals()
            )
            return locals()['result']