Urgent.News

What's breaking now, across thousands of outlets.

Tech

No more messy f-strings: Type-safe fluent SQL for ClickHouse.

No more messy f-strings: Type-safe fluent SQL for ClickHouse. Day 08 of the WClickHouse Open-Source Engineering Series. Building dynamic analytical queries by stitching f-strings together is an accident waiting to happen. WClickHouse QueryBuilder gives you fluent, safe SQL composition. The Pain Points We Faced Brittle multi-line SQL strings full of dangerous f-string formatting and syntax typos…

Avoiding messy f-strings: Fluent SQL for ClickHouse. Moving past Day 8 of the WClickHouse Open-Source Engineering Series, QueryBuilder offers type-safe, fluent SQL composition. Brittle, multi-line SQL strings plagued by formatting errors and syntax typos. Unescaped dynamic query parameters posed SQL injection risks. Code reusability became difficult for dynamic dashboards with conditional filters.

Implementation begins with `from wclickhouse import QueryBuilder`. The `QueryBuilder()` is instantiated, forming the foundation for query creation. Queries are built using chained API methods: `table()`, `select()`, `where()`, `group_by()`, `having()`, `order_by()`, and `limit()`. These methods allow for a natural, readable flow in constructing complex queries.

Injection protection is automatic, with parameters being escaped and validated. Advanced operators, such as joins, `union_all()`, and subqueries, are also natively supported. The implementation has been thoroughly tested and verified against live ClickHouse server instances, boasting over 95% test coverage.

The framework is built for Python versions 3.9 through 3.14, leveraging Apache Arrow and Pydantic v2. For further information, visit the GitHub repository (https://github.com/wisrovi/wclickhouse) or PyPI page (https://pypi.org/project/wclickhouse).

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in Tech

Your Next.js API route is public—even if your UI isn’t.

Hiding a form behind a client-side condition doesn't make its API route private. Unless the route enforces its own checks, another client can call it directly.

  • Public API routes in Next.js are accessible even if UI is not visible.
  • Unauthorized data submission possible via direct URL access.
  • FCaptcha provides server-side form verification solution.

More from Monday 28 September →