Since #1121, RedisProvider.query() refuses the blocking commands before they reach the server (sharedConnectionRefusal in src/lib/db/providers/keyvalue/redis.ts, documented in section 5.2b of docs/providers/redis.md).
The editor's confirmation gate still lists eight of them as destructive, so a user who runs one is first asked to confirm, and after confirming is told it will not run.
Repro
- Run Studio with a Redis connection, log in and open the connection.
- Type
BLPOP queue 0 in the editor and run it.
- The "Query Safety Check" dialog opens: "This statement may change data, database objects, or permissions."
- Click "Execute Query". The results panel says
BLPOP is not run here: every other request on the shared connection would wait until it returns.
Expected: no dialog, just the refusal, the way SUBSCRIBE ch behaves today.
Why
REDIS_DESTRUCTIVE_COMMANDS in src/lib/db/destructive-commands.ts contains BLPOP, BRPOP, BLMPOP, BLMOVE, BRPOPLPUSH, BZPOPMIN, BZPOPMAX and BZMPOP.
The file's own scope rule says it names only what each provider can really run, and the docblock above the set says every name can reach the server because runCommand has no allow-list.
Both stopped being true with #1121.
What to do
- Remove those eight names from
REDIS_DESTRUCTIVE_COMMANDS.
Keep their non-blocking forms (LPOP, RPOP, LMPOP, LMOVE, RPOPLPUSH, ZPOPMIN, ZPOPMAX, ZMPOP): the provider runs those, and they are destructive.
- Rewrite the docblock paragraph that starts "Every name here can reach the server".
It should say that the provider refuses some commands before they reach the server, and point to sharedConnectionRefusal in src/lib/db/providers/keyvalue/redis.ts and to section 5.2b of docs/providers/redis.md.
Name the file and the symbol, not a line number.
- In
tests/unit/db/destructive-commands.test.ts, add a test next to "names no MongoDB operation the provider cannot dispatch", in the same shape: the Redis set contains none of the eight names.
Also add an isDestructiveNonSqlQuery("BLPOP queue 0", "redis") case that expects false, and one for a non-blocking form, such as LPOP queue, that still expects true.
Write the tests first and check that they fail before you change the set.
Do not change redis.ts or the Redis provider tests.
Do not use em dashes or en dashes.
Acceptance criteria
Since #1121,
RedisProvider.query()refuses the blocking commands before they reach the server (sharedConnectionRefusalinsrc/lib/db/providers/keyvalue/redis.ts, documented in section 5.2b ofdocs/providers/redis.md).The editor's confirmation gate still lists eight of them as destructive, so a user who runs one is first asked to confirm, and after confirming is told it will not run.
Repro
BLPOP queue 0in the editor and run it.BLPOP is not run here: every other request on the shared connection would wait until it returns.Expected: no dialog, just the refusal, the way
SUBSCRIBE chbehaves today.Why
REDIS_DESTRUCTIVE_COMMANDSinsrc/lib/db/destructive-commands.tscontainsBLPOP,BRPOP,BLMPOP,BLMOVE,BRPOPLPUSH,BZPOPMIN,BZPOPMAXandBZMPOP.The file's own scope rule says it names only what each provider can really run, and the docblock above the set says every name can reach the server because
runCommandhas no allow-list.Both stopped being true with #1121.
What to do
REDIS_DESTRUCTIVE_COMMANDS.Keep their non-blocking forms (
LPOP,RPOP,LMPOP,LMOVE,RPOPLPUSH,ZPOPMIN,ZPOPMAX,ZMPOP): the provider runs those, and they are destructive.It should say that the provider refuses some commands before they reach the server, and point to
sharedConnectionRefusalinsrc/lib/db/providers/keyvalue/redis.tsand to section 5.2b ofdocs/providers/redis.md.Name the file and the symbol, not a line number.
tests/unit/db/destructive-commands.test.ts, add a test next to "names no MongoDB operation the provider cannot dispatch", in the same shape: the Redis set contains none of the eight names.Also add an
isDestructiveNonSqlQuery("BLPOP queue 0", "redis")case that expectsfalse, and one for a non-blocking form, such asLPOP queue, that still expectstrue.Write the tests first and check that they fail before you change the set.
Do not change
redis.tsor the Redis provider tests.Do not use em dashes or en dashes.
Acceptance criteria
REDIS_DESTRUCTIVE_COMMANDS, and the eight non-blocking forms are still there.bun tests/run-tests.ts tests/unit/db/destructive-commands.test.ts tests/components/QuerySafetyDialog.test.tsxpasses.bun run lintandbun run typecheckpass.BLPOP queue 0on a Redis connection shows the refusal with no dialog, andLPOP queuestill asks. Put a screenshot of each in the PR.