Class: QueryGuard::Analysis::UnionRiskDetector
- Inherits:
-
RiskDetector
- Object
- RiskDetector
- QueryGuard::Analysis::UnionRiskDetector
- Defined in:
- lib/query_guard/analysis/risk_detectors.rb
Overview
Detects UNION queries (can be slower than OR)
Constant Summary collapse
- UNION_PATTERN =
/\bUNION\b/i.freeze
Instance Attribute Summary
Attributes inherited from RiskDetector
Instance Method Summary collapse
- #detect(query, config) ⇒ Object
-
#initialize ⇒ UnionRiskDetector
constructor
A new instance of UnionRiskDetector.
Constructor Details
#initialize ⇒ UnionRiskDetector
Returns a new instance of UnionRiskDetector.
192 193 194 |
# File 'lib/query_guard/analysis/risk_detectors.rb', line 192 def initialize super(:union_risk) end |
Instance Method Details
#detect(query, config) ⇒ Object
196 197 198 199 200 201 202 203 204 205 206 207 208 209 210 211 212 213 214 215 |
# File 'lib/query_guard/analysis/risk_detectors.rb', line 196 def detect(query, config) risks = [] return risks unless matches_pattern?(query.sql, UNION_PATTERN) # UNION ALL is better than UNION (no sorting) has_union_all = query.sql.match?(/\bUNION\s+ALL\b/i) risks << { pattern: :union_query, risk_level: has_union_all ? :low : :medium, message: "UNION #{'ALL' if has_union_all} query; consider OR clause or application-level merging", metadata: { has_union_all: has_union_all, recommendation: has_union_all ? "Consider OR instead" : "Use UNION ALL instead of UNION", impact: "Sorting overhead if UNION (not ALL)" } } risks end |