korbit-ai[bot] commented on code in PR #34413: URL: https://github.com/apache/superset/pull/34413#discussion_r2243968703
########## superset/sql_parse.py: ########## @@ -88,7 +88,9 @@ # reference: https://sqlparse.readthedocs.io/en/stable/extending/ lex = Lexer.get_default_instance() sqlparser_sql_regex = keywords.SQL_REGEX -sqlparser_sql_regex.insert(25, (r"'(''|\\\\|\\|[^'])*'", sqlparse.tokens.String.Single)) +sqlparser_sql_regex.insert( + 25, (r"'(?:[^'\\]|\\\\?|'')*'", sqlparse.tokens.String.Single) +) Review Comment: ### Undocumented Complex Regex Pattern <sub></sub> <details> <summary>Tell me more</summary> ###### What is the issue? Complex regex pattern without explanation of what it matches and each component's purpose. ###### Why this matters Without understanding the regex components, future maintainers will struggle to modify or debug the pattern safely, especially given its security implications for ReDOS protection. ###### Suggested change ∙ *Feature Preview* Add a clear comment explaining the regex pattern: ```python # Regex for matching SQL single-quoted strings: # '(?:[^'\\]|\\\\?|'')*' # - [^'\\]: Any char except quote or backslash # - \\\\?: Optional escaped backslash # - '': Escaped single quote # Together this safely matches SQL strings while preventing ReDOS sqlparser_sql_regex.insert( 25, (r"'(?:[^'\\]|\\\\?|'')*'", sqlparse.tokens.String.Single) ) ``` ###### Provide feedback to improve future suggestions [](https://app.korbit.ai/feedback/aa91ff46-6083-4491-9416-b83dd1994b51/1a1ad62c-1f4d-4b6e-8131-4340df835437/upvote) [](https://app.korbit.ai/feedback/aa91ff46-6083-4491-9416-b83dd1994b51/1a1ad62c-1f4d-4b6e-8131-4340df835437?what_not_true=true) [](https://app.korbit.ai/feedback/aa91ff46-6083-4491-9416-b83dd1994b51/1a1ad62c-1f4d-4b6e-8131-4340df835437?what_out_of_scope=true) [](https://app.korbit.ai/feedback/aa91ff46-6083-4491-9416-b83dd1994b51/1a1ad62c-1f4d-4b6e-8131-4340df835437?what_not_in_standard=true) [](https://app.korbit.ai/feedback/aa91ff46-6083-4491-9416-b83dd1994b51/1a1ad62c-1f4d-4b6e-8131-4340df835437) </details> <sub> 💬 Looking for more details? Reply to this comment to chat with Korbit. </sub> <!--- korbi internal id:f5ff278f-0021-4f1a-b304-9cd7f6a72473 --> [](f5ff278f-0021-4f1a-b304-9cd7f6a72473) -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected] --------------------------------------------------------------------- To unsubscribe, e-mail: [email protected] For additional commands, e-mail: [email protected]
