Skip to content

Guard user data from registered files, dashboards and apps; per-tab r… - #1

Merged
JetSquirrel merged 1 commit into
mainfrom
review-fixes
Sep 23, 2026
Merged

JetSquirrel merged 1 commit into
mainfrom
review-fixes

Conversation

@JetSquirrel

Copy link
Copy Markdown
Owner

…esults

  • re-attaching a registered file never replaces a table or view the user made: DuckLocal tags what it creates with a catalog comment and reports a name clash instead of CREATE OR REPLACE over the user's relation
  • .dash queries must be one read-only statement (DuckDB's own json_serialize_sql judgement, PIVOT allowed); the GUI refuses anything else before it runs, and check/lsp report it as a diagnostic
  • an app folder asks "Trust and run" once before any of its code or SQL runs; the answer is remembered per folder in settings
  • each query tab owns its results panel, and a run lands in the tab that started it, so export uses that tab's SQL
  • non-UTF-8 command-line paths no longer panic the GUI launch
  • docs and skill updated for the dashboard and app rules

…esults

- re-attaching a registered file never replaces a table or view the user
  made: DuckLocal tags what it creates with a catalog comment and reports
  a name clash instead of CREATE OR REPLACE over the user's relation
- .dash queries must be one read-only statement (DuckDB's own
  json_serialize_sql judgement, PIVOT allowed); the GUI refuses anything
  else before it runs, and check/lsp report it as a diagnostic
- an app folder asks "Trust and run" once before any of its code or SQL
  runs; the answer is remembered per folder in settings
- each query tab owns its results panel, and a run lands in the tab that
  started it, so export uses that tab's SQL
- non-UTF-8 command-line paths no longer panic the GUI launch
- docs and skill updated for the dashboard and app rules

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@JetSquirrel
JetSquirrel merged commit d438c5a into main Sep 23, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant