aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorAlex Browne <stephenalexbrowne@gmail.com>2018-11-17 05:16:17 +0800
committerFred Carlsen <fred@sjelfull.no>2018-12-06 19:04:25 +0800
commit80ab797d3ab409e29bcd9b99ddb57c14a5849a19 (patch)
treea48c0682f405133443c8114dbfbc04e54e05e85e
parentd6dff5f86a40bc36d43cfce55c1d408a856735b1 (diff)
downloaddexon-0x-contracts-80ab797d3ab409e29bcd9b99ddb57c14a5849a19.tar
dexon-0x-contracts-80ab797d3ab409e29bcd9b99ddb57c14a5849a19.tar.gz
dexon-0x-contracts-80ab797d3ab409e29bcd9b99ddb57c14a5849a19.tar.bz2
dexon-0x-contracts-80ab797d3ab409e29bcd9b99ddb57c14a5849a19.tar.lz
dexon-0x-contracts-80ab797d3ab409e29bcd9b99ddb57c14a5849a19.tar.xz
dexon-0x-contracts-80ab797d3ab409e29bcd9b99ddb57c14a5849a19.tar.zst
dexon-0x-contracts-80ab797d3ab409e29bcd9b99ddb57c14a5849a19.zip
Check for special characters in table name in pull_missing_events
-rw-r--r--packages/pipeline/src/scripts/pull_missing_events.ts10
1 files changed, 7 insertions, 3 deletions
diff --git a/packages/pipeline/src/scripts/pull_missing_events.ts b/packages/pipeline/src/scripts/pull_missing_events.ts
index b2a99e3c0..0b7f6287f 100644
--- a/packages/pipeline/src/scripts/pull_missing_events.ts
+++ b/packages/pipeline/src/scripts/pull_missing_events.ts
@@ -64,16 +64,20 @@ async function getCancelUpToEventsAsync(eventsSource: ExchangeEventsSource): Pro
await saveEventsAsync(startBlock === EXCHANGE_START_BLOCK, repository, events);
}
+const tabelNameRegex = /^[a-zA-Z_]*$/;
+
async function getStartBlockAsync<T extends ExchangeEvent>(repository: Repository<T>): Promise<number> {
const fillEventCount = await repository.count();
if (fillEventCount === 0) {
console.log(`No existing ${repository.metadata.name}s found.`);
return EXCHANGE_START_BLOCK;
}
+ const tableName = repository.metadata.tableName;
+ if (!tabelNameRegex.test(tableName)) {
+ throw new Error('Unexpected special character in table name: ' + tableName);
+ }
const queryResult = await connection.query(
- // TODO(albrow): Would prefer to use a prepared statement here to reduce
- // surface area for SQL injections, but it doesn't appear to be working.
- `SELECT block_number FROM raw.${repository.metadata.tableName} ORDER BY block_number DESC LIMIT 1`,
+ `SELECT block_number FROM raw.${tableName} ORDER BY block_number DESC LIMIT 1`,
);
const lastKnownBlock = queryResult[0].block_number;
return lastKnownBlock - START_BLOCK_OFFSET;