Hacktoberfest 2026: le issue che i maintainer hanno segnato per ottobre, aperte e adatte ai principianti. Sfoglia le issue Hacktoberfest

RE2-unsafe regex patterns: audit production segments and decide fallback policy

Aperta
#3 1 commento 0 reazioni 0 assegnatari Vedi su GitHub

Nessuno ha ancora preso questa issue.

Valutazione

Difficoltà
5/5
Tempo stimato
Più di una settimana
Idoneità per principianti
45/100
Tipo di issue
Funzionalità
Chiarezza
Abbastanza chiara
Stato di attività
Tranquilla
Stack tecnologico
python, sql

Direzione di ricerca

Inizia da _RE2_UNSAFE in src/flagsmith_sql_flag_engine/translator.py e ispeziona la suite engine-test-data. Esegui l’audit REGEXP_LIKE proposto sulla colonna JSON rules della tabella segments per misurare l’uso di backreference e lookaround. Il lavoro è completato quando la prevalenza è stata registrata, è stata scelta una policy di fallback e il comportamento corrispondente è stato implementato e validato.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Descrizione

The translator returns None for any REGEX condition whose pattern contains:

  • Backreferences (\1–\9)
  • Lookarounds ((?=, (?!, (?<=, (?<!)

Snowflake uses RE2, which doesn't support either feature. The detection is conservative-syntactic in _RE2_UNSAFE (src/flagsmith_sql_flag_engine/translator.py).

The engine-test-data suite doesn't include any RE2-unsafe patterns, currently.

What to do

  1. Audit production segment definitions for either pattern — REGEXP_LIKE over the segments table's rules JSON column with a pattern that catches \1–\9 or (?=/(?!/(?<=/(?<! as substrings. Cheap query, gives a real prevalence number.
  2. Decide fallback policy based on prevalence:
    • If essentially nobody uses these features (most likely): surface the error at segment-edit time. The Flagsmith UI rejects the pattern with a clear "Snowflake-backed envs do not support backreferences / lookarounds" message. Translator's None return becomes an unreachable defensive branch.
    • If non-trivial usage: ship a fallback that runs the pattern through the Python flag_engine just for those segments, e.g. by calling out to an is_in_segment UDF. Adds back the per-row Python tax but only for the affected segments.
Lingua principale
Python
Stelle
1
Fork
0
Metriche di merge delle PR
Nessuna PR unita negli ultimi 30g

Preparare l'ambiente

  • Include un Dockerfile o un file Docker Compose
  • Nessun modello di pull request
  • Nessuna guida per i contributori

Come iniziare

  1. Leggi tutta la issue e poi la guida ai contributi del progetto.
  2. Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
  3. Fai un fork del repository e lavora su un branch.
  4. Apri una pull request che faccia riferimento al numero della issue.

Altre issue di Flagsmith/flagsmith-sql-flag-engine

Tutte le issue di Flagsmith/flagsmith-sql-flag-engine

Issue simili

Altre issue su Python

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.