Repository navigation
fix: ignore quoted SQL when binding native parameters - #348
Merged
Merged
Conversation
RequestFactory scanned quoted filter values as typed parameter declarations, causing UnsupportedParamType for literal placeholder-shaped text. Skip quoted strings, identifiers, comments, and heredocs during extraction. Preserve the original SQL, real parameter bindings, and nested type arguments.
Replace the combined regex with a stack-safe lexical scanner. Preserve Unicode content, dollar-bearing identifiers, escaped quotes, nested comments, and real bindings after large SQL tokens. Index heredoc delimiters once to avoid repeated whole-query searches. Report parameter-pattern errors instead of silently dropping bindings.
Codecov Report❌ Patch coverage is
Additional details and impacted files@@ Coverage Diff @@
## master #348 +/- ##
==========================================
+ Coverage 96.05% 96.29% +0.24%
==========================================
Files 42 43 +1
Lines 862 945 +83
==========================================
+ Hits 828 910 +82
- Misses 34 35 +1 ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
Move lexical and type-selection cases into NativeParameterParserTest. Keep the request-level plain SQL body check without duplicating parser scenarios. Cover empty lexical tokens, Unicode operators, and heredocs after real bindings. Use balanced quotes inside ignored text so quote handling cannot mask missing comment or heredoc recognition.
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
Hash comments without a following space remain incorrectly scanned for parameters.
Review effort: Balanced
Findings: 1
Open (1)
What changed in this PR
Introduces lexical native-parameter parsing so quoted or commented placeholder text is ignored.
Changes:
- Adds quote, comment, and heredoc-aware parameter scanning.
- Integrates the parser into HTTP request preparation.
- Adds parser and regression tests.
| File | Description |
|---|---|
src/Sql/NativeParameterParser.php |
Implements lexical parameter extraction. |
src/Client/Http/RequestFactory.php |
Uses the new parser. |
tests/Sql/NativeParameterParserTest.php |
Covers parser syntax and edge cases. |
tests/Client/Http/RequestFactoryTest.php |
Verifies quoted placeholders remain plain SQL. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Cover partial dollar-bearing identifiers and adjacent nested comment delimiters. Verify that comment scanning preserves a following division operator and that valid query text does not emit boundary warnings.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

RequestFactory treats placeholder-shaped text inside quoted values as native parameter declarations. A filter value such as
{context:UnknownType}can therefore throwUnsupportedParamTypebefore the query is sent.Extract native bindings with a lexical scanner that skips strings, quoted identifiers, comments, and heredocs while preserving the original SQL. Handle escapes, Unicode quotes, nested comments, and dollar-bearing identifiers. Index heredoc delimiters once to avoid repeated whole-query searches.
The separate legacy
:namesubstitution path in SqlFactory remains unchanged; it still does not distinguish quoted text from SQL code.