Skip to content

Use PEP 675 LiteralString to refine database function annotations #13473

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
matrixbot opened this issue Dec 20, 2023 · 0 comments
Open

Use PEP 675 LiteralString to refine database function annotations #13473

matrixbot opened this issue Dec 20, 2023 · 0 comments

Comments

@matrixbot
Copy link
Collaborator

matrixbot commented Dec 20, 2023

This issue has been migrated from #13473.


PEP 675 proposes a new typing.LiteralString type. The idea is that typecheckers should check that a LiteralString is composed only from string literals (i.e. cannot contain user-provided data), to help mitigate e.g. SQL injection attacks. This sounds like a nice-to-have for us, though it's probably not worth picking up until mypy has support for the type (python/mypy#12554).

@matrixbot matrixbot changed the title Dummy issue Use PEP 675 LiteralString to refine database function annotations Dec 21, 2023
@matrixbot matrixbot reopened this Dec 21, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

1 participant