Class: QueryGuard::Analysis::UnionRiskDetector

Inherits:
RiskDetector
  • Object
show all
Defined in:
lib/query_guard/analysis/risk_detectors.rb

Overview

Detects UNION queries (can be slower than OR)

Constant Summary collapse

UNION_PATTERN =
/\bUNION\b/i.freeze

Instance Attribute Summary

Attributes inherited from RiskDetector

#name

Instance Method Summary collapse

Constructor Details

#initialize ⇒ UnionRiskDetector

Returns a new instance of UnionRiskDetector.



192
193
194
# File 'lib/query_guard/analysis/risk_detectors.rb', line 192

def initialize
  super(:union_risk)
end

Instance Method Details

#detect(query, config) ⇒ Object



196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
# File 'lib/query_guard/analysis/risk_detectors.rb', line 196

def detect(query, config)
  risks = []
  return risks unless matches_pattern?(query.sql, UNION_PATTERN)

  # UNION ALL is better than UNION (no sorting)
  has_union_all = query.sql.match?(/\bUNION\s+ALL\b/i)

  risks << {
    pattern: :union_query,
    risk_level: has_union_all ? :low : :medium,
    message: "UNION #{'ALL' if has_union_all} query; consider OR clause or application-level merging",
    metadata: {
      has_union_all: has_union_all,
      recommendation: has_union_all ? "Consider OR instead" : "Use UNION ALL instead of UNION",
      impact: "Sorting overhead if UNION (not ALL)"
    }
  }

  risks
end