pejrich
I’ve always wondered this and while reading the docs again I was curious about why this is left to the user. The docs say:
This is done as a security measure to avoid attacks that attempt to traverse entries with nil columns.
To check that value is nil, use is_nil/1 instead:
I’m curious about 2 things.
- What is the attack it refers to, and how does
is_nil/1thwart the attack in a way that==doesn’t? - Since nil comparisons raise an error if done with
==, why is the implementation of checking for nil, and usingis_nilor==based on the results left up to the user rather than handled internally in the lib? Couldn’t the Ecto.Query.Builder.not_nil!/1 check be amended to instead resolve the final query to either==ornot_nil/1based on the runtime value?
Genuinely curious, not a complaint.
Trending in Questions
I’m working on a project that simulates the bumbl example in the programming phoenix book. It acts almost like an email client. We have a...
New
Hi everyone,
I am toying with the idea of building a “match maker” for giving personal help to people that wants to start coding.
I sta...
New
Hello,
I know there is an approach for handling lists that allows for optimized traversal, but I can’t recall the specific method (somet...
New
Documentation
While reading the Scoped Routes section, I noticed that the documentation currently refers to a problem without explainin...
New
So my question is quite simple and i have found no conclusive answer on forum, google or AI.
Should we use :erlang.float for Integer to ...
New
I recently noticed that Elixir’s Logger defaults its primary log level to :debug when no :logger, :level application configuration is pre...
New
apply_graft/2 doesn’t rewrite an add_many sub-workflow’s deps on an add step. Grafted jobs cancel with “upstream job was deleted”
Version...
New
Other Trending Topics
Hey, I’m Jesse and I’m the main contributor behind Dexter, a full-featured, lightning-fast Elixir LSP optimized for large codebases. It s...
New
Hi there! We created Gust: A task orchestrator inspired by Airflow.
For those who have never heard about Aiflow, it’s a Python-based wor...
New
Hi everyone!
The first release candidate for the Expert language server project is now available!
We’ve published a press release detai...
New
Beam Bots (or just BB for short) is a framework for building fault-tolerant robotics applications in Elixir using familiar OTP patterns. ...
New
Xamal is a deployment tool for Elixir apps that deploys native releases to bare metal servers over SSH. It’s a port of GitHub - basecamp/...
New
With AI doing more of the implementation work, I’ve been wondering how much coding I should deliberately keep doing myself.
My main conc...
New
Categories:
Sub Categories:
Forums
Popular Tags
- #ecto
- #liveview
- #troubleshooting
- #learning-elixir
- #library
- #deployment
- #erlang
- #testing
- #genserver
- #mix
- #absinthe
- #remote-other
- #otp
- #plug
- #how-to-question
- #macros
- #postgres
- #elixirconf
- #channels
- #exunit
- #discussion
- #code-sync
- #podcasts
- #javascript
- #onsite
- #dialyzer
- #docker
- #authentication
- #umbrella
- #full-time-contract
- #podcasts-by-brainlid
- #ecto-query
- #elixirconf-us
- #ai
- #blog-post
- #elixir-ls
- #phoenix_html
- #iex
- #graphql
- #genstage
- #websockets
- #supervisor
- #advent-of-code
- #distillery
- #processes
- #api
- #forms
- #elixirconf-eu
- #metaprogramming
- #hex










Showing Posts 1 to 4- Show Best Posts
- Show All (oldest first)
- Show All (newest first)
josevalim
Imagine you write this query:
Now if someone passes no token, you will accidentally login as any of the users without a token.
pejrich
Ahhh, so
is_nil/1doesn’t really need to handle things differently, it’s more of a guardrail so users have to explicitly opt in if they want nil, rather than accidentally exposing these security holes? It’s still a rather verbose way to handle it. Something likewhere: p.column == nilable(^var)would lead to cleaner code, rather than having a case statement with a nil case and a non-nil case.josevalim
That doesn’t work at the SQL level though as most people expect, you can’t compare with NULL, it is always false.
hauleth
The thing is that
NULLis a little bit unfortunate name in the DB.NULLin the DB mean that we do not know value of this field, not that it is “empty”. One unknown value is not equal to another unknown value, similar toNaN != NaNin IEEE754. We cannot tell that 2NULLs in the DB are equal, because we do not know what they value should be.Imagine that you have table like:
(
∅here mean null value)Can we tell that Bob and Dan have the same occupation? No, because we do not know what their occupation is, it is different from being unemployed.
Your approach would make it confusing in situations like:
And while we could secure user a little bit against the above, the one below is not possible without explicit user intent:
While there is no safeguard in Ecto against the latter, the whole nature of the fact that you need to use
is_nil/1in favour ofa.foo == nilis something that make people think a little about that case.