Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
32 changes: 21 additions & 11 deletions src/node_sqlite.cc
Original file line number Diff line number Diff line change
Expand Up @@ -284,7 +284,9 @@ MaybeLocal<Object> CreateSQLiteErrorImpl(Isolate* isolate,
Local<Context> context = isolate->GetCurrentContext();
Local<String> js_msg;
Local<Object> e;
if (!String::NewFromUtf8(isolate, message).ToLocal(&js_msg) ||
// SQLite error messages embed the offending identifier or token, so they
// can exceed String::kMaxLength.
if (!Utf8StringMaybeOneByte(isolate, message).ToLocal(&js_msg) ||
!Exception::Error(js_msg)->ToObject(context).ToLocal(&e) ||
e->Set(context, env->code_string(), env->err_sqlite_error_string())
.IsNothing()) {
Expand Down Expand Up @@ -399,7 +401,15 @@ inline MaybeLocal<Value> NullableSQLiteStringToValue(Isolate* isolate,
return Null(isolate);
}

return String::NewFromUtf8(isolate, str, NewStringType::kInternalized)
// With the default length of -1, V8 aborts on strings over kMaxLength.
const size_t len = strlen(str);
if (len > static_cast<size_t>(String::kMaxLength)) [[unlikely]] {
isolate->ThrowException(node::ERR_STRING_TOO_LONG(isolate));
return MaybeLocal<Value>();
}

return String::NewFromUtf8(
isolate, str, NewStringType::kInternalized, static_cast<int>(len))
.As<Value>();
}

Expand Down Expand Up @@ -3631,15 +3641,15 @@ int Database::AuthorizerCallback(void* user_data,

Local<Function> callback = cb.As<Function>();

LocalVector<Value> js_argv(
isolate,
{
Integer::New(isolate, action_code),
NullableSQLiteStringToValue(isolate, param1).ToLocalChecked(),
NullableSQLiteStringToValue(isolate, param2).ToLocalChecked(),
NullableSQLiteStringToValue(isolate, param3).ToLocalChecked(),
NullableSQLiteStringToValue(isolate, param4).ToLocalChecked(),
});
LocalVector<Value> js_argv(isolate, {Integer::New(isolate, action_code)});
for (const char* param : {param1, param2, param3, param4}) {
Local<Value> arg;
if (!NullableSQLiteStringToValue(isolate, param).ToLocal(&arg)) {
db->SetIgnoreNextSQLiteError(true);
return SQLITE_DENY;
}
js_argv.push_back(arg);
}

MaybeLocal<Value> retval = callback->Call(
context, Undefined(isolate), js_argv.size(), js_argv.data());
Expand Down
30 changes: 29 additions & 1 deletion test/parallel/test-sqlite-statement.js
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,11 @@
'use strict';
const { enoughTestMem, skipIfSQLiteMissing } = require('../common');
skipIfSQLiteMissing();
const { Database, Statement } = require('node:sqlite');
const {
Database,
Statement,
constants: { SQLITE_OK },
} = require('node:sqlite');
const { constants } = require('node:buffer');
const { suite, test } = require('node:test');

Expand Down Expand Up @@ -1448,6 +1452,9 @@ suite('values larger than the maximum string length', { skip: !enoughTestMem },
// hex() doubles its input, so this is the smallest blob whose text form
// exceeds what V8 can hold in a string.
const blobSize = (constants.MAX_STRING_LENGTH >>> 1) + 1;
// '\u20ac' is 1 UTF-16 code unit but 3 UTF-8 bytes, so this identifier is a
// valid JS string whose UTF-8 form exceeds the limit.
const longIdentifier = '\u20ac'.repeat(Math.ceil(constants.MAX_STRING_LENGTH / 3) + 10);
const tooLong = { code: 'ERR_STRING_TOO_LONG', name: 'Error' };

test('get() throws instead of returning undefined', (t) => {
Expand All @@ -1458,6 +1465,27 @@ suite('values larger than the maximum string length', { skip: !enoughTestMem },
}, tooLong);
});

test('prepare() throws when the SQLite error message is too long', (t) => {
using db = new Database(':memory:');
// SQLite repeats the identifier in the error.
t.assert.throws(() => {
db.prepare(`SELECT 1 FROM "${longIdentifier}"`);
}, tooLong);
});

test('prepare() throws for an oversized authorizer argument', (t) => {
using db = new Database(':memory:');
db.setAuthorizer(() => SQLITE_OK);
t.assert.throws(() => db.prepare(`CREATE TABLE "${longIdentifier}" (x)`), tooLong);
});

test('columns() throws for an oversized declared type', (t) => {
using db = new Database(':memory:');
db.exec(`CREATE TABLE t (x "${longIdentifier}")`);
using stmt = db.prepare('SELECT x FROM t');
t.assert.throws(() => stmt.columns(), tooLong);
});

test('exec() surfaces the error from a user-defined function', (t) => {
using db = new Database(':memory:');
db.exec('CREATE TABLE data(val TEXT)');
Expand Down
Loading