Skip to content

Redis: the confirmation dialog asks about blocking commands the provider now refuses #1164

Description

@cevheri

Since #1121, RedisProvider.query() refuses the blocking commands before they reach the server (sharedConnectionRefusal in src/lib/db/providers/keyvalue/redis.ts, documented in section 5.2b of docs/providers/redis.md).
The editor's confirmation gate still lists eight of them as destructive, so a user who runs one is first asked to confirm, and after confirming is told it will not run.

Repro

  1. Run Studio with a Redis connection, log in and open the connection.
  2. Type BLPOP queue 0 in the editor and run it.
  3. The "Query Safety Check" dialog opens: "This statement may change data, database objects, or permissions."
  4. Click "Execute Query". The results panel says BLPOP is not run here: every other request on the shared connection would wait until it returns.

Expected: no dialog, just the refusal, the way SUBSCRIBE ch behaves today.

Why

REDIS_DESTRUCTIVE_COMMANDS in src/lib/db/destructive-commands.ts contains BLPOP, BRPOP, BLMPOP, BLMOVE, BRPOPLPUSH, BZPOPMIN, BZPOPMAX and BZMPOP.
The file's own scope rule says it names only what each provider can really run, and the docblock above the set says every name can reach the server because runCommand has no allow-list.
Both stopped being true with #1121.

What to do

  1. Remove those eight names from REDIS_DESTRUCTIVE_COMMANDS.
    Keep their non-blocking forms (LPOP, RPOP, LMPOP, LMOVE, RPOPLPUSH, ZPOPMIN, ZPOPMAX, ZMPOP): the provider runs those, and they are destructive.
  2. Rewrite the docblock paragraph that starts "Every name here can reach the server".
    It should say that the provider refuses some commands before they reach the server, and point to sharedConnectionRefusal in src/lib/db/providers/keyvalue/redis.ts and to section 5.2b of docs/providers/redis.md.
    Name the file and the symbol, not a line number.
  3. In tests/unit/db/destructive-commands.test.ts, add a test next to "names no MongoDB operation the provider cannot dispatch", in the same shape: the Redis set contains none of the eight names.
    Also add an isDestructiveNonSqlQuery("BLPOP queue 0", "redis") case that expects false, and one for a non-blocking form, such as LPOP queue, that still expects true.

Write the tests first and check that they fail before you change the set.
Do not change redis.ts or the Redis provider tests.
Do not use em dashes or en dashes.

Acceptance criteria

  • The eight blocking names are gone from REDIS_DESTRUCTIVE_COMMANDS, and the eight non-blocking forms are still there.
  • The docblock no longer says that every name reaches the server.
  • The new tests fail on main and pass with the change.
  • bun tests/run-tests.ts tests/unit/db/destructive-commands.test.ts tests/components/QuerySafetyDialog.test.tsx passes.
  • bun run lint and bun run typecheck pass.
  • In the app, BLPOP queue 0 on a Redis connection shows the refusal with no dialog, and LPOP queue still asks. Put a screenshot of each in the PR.

Activity

  1. added
    bugSomething isn't working
    hacktoberfestCurated for Hacktoberfest; pick up cold, tests required
    on Sep 27, 2026
  2. niukanen1 commented on Sep 28, 2026

    @niukanen1
    Contributor

    I'll take this one

  3. added theissue type on Sep 28, 2026
  4. added
    enhancementNew feature or request
    and removed
    bugSomething isn't working
    on Sep 28, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

enhancementNew feature or requestgood first issueGood for newcomershacktoberfestCurated for Hacktoberfest; pick up cold, tests requiredredis

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions