Show HN: Django SQL Explorer
github.com
github.com
I spend a lot of time writing intranet CRUD apps and these kinds of tools can be really useful to give your users access to the raw data so they can export to csv & do their own analysis in Excel (or whatever their tool of choice).
Thanks a bunch for open sourcing it!
On the security front, the SQL blacklist definitely has to go. It's a false sense of security (ex: string concat + dynamic execution gets around it). The suggestion to use a read only user is a good one but even better is to use a read only database (ex: a Postgres replication slave).
Have you checked out JackDB? (http://www.jackdb.com/ full disclosure: I'm the founder) It's a full featured database client that runs entirely in your browser.
RE: circumventing the blacklist, I think immediately of accessing a function with postgresql aka select my_destructive_function();
The blacklist has no chance of defending against malicious users. Luckily (at the moment) we are using this purely internally and the blacklist is really just preventing people from shooting themselves in the foot. We're moving to a read-only user role shortly, and the suggestion to go with a read-only db is a great one.
I would love to try using this with Schemaverse (http://schemaverse.com) but most frameworks I have seen have trouble with multiple database roles/connections.
EXPLORER_CONNECTION_NAME
And give it the name of the django connection you want to use. We are in the process of moving from Heroku Postgresql (which only supports a single DB user) to Amazon RDS Postgres specifically for this capability. It will ensure that users of SQL Explorer have read-only access (something that is currently enforced by a SQL blacklist - a risky approach)Luckily, I don't need to care about read-only or blacklisted queries, the entire application is already built into the database layer.
Unfortunately there is NOT currently a way via configuration to allow the general public to access queries - it's locked down the Django admins by default. But it's just a matter of removing some view decorators to change that. Maybe something for me to add in a future version...
Anyway, let me know if you need any help.
Thanks!
Another tool, different, but also great for sharing, you may enjoy: http://htsql.org/
Adoption was good especially for simple queries, people were less focused on the language, and more focused on exploring/modifying examples.
For people who are already familiar with SQL and as you said, less interested in the query language, it may be almost immediately frustrating.
I can absolutely see circumstances where it would be overkill, I have never tried to use it as a performance critical tool, just as more an easy thing to slap on to ease access, two aspects that I have found useful on more than one occasion:
1. HTRAF toolkit is convenient for very basic visualization (depending upon the audience this can be very useful to have at hand quickly)
2. multiple output formats (json in particular) has been helpful in terms of quickly hacking together prototypes in the past