|
Documenting this here because it comes up often — if your situation is different, please reply in this thread. The plan is to let a model translate a user question into a query. The two things I am worried about are (a) the model inventing a query that reads data the user should not see, and (b) SQL injection through the generated string. |
Answered by
coenddt
Sep 14, 2026
Replies: 1 comment
|
Planning is a pure function — GQL + params in, MongoDB command JSON out — so a model's output can be compiled, validated and rejected before anything touches a database. const gql = 'Order($condition:@c0,$sort:@s1,$limit:@l) { code, amount }';
const params = { c0: { amount: { $gte: 100 } }, s1: { amount: -1 }, l: 20 };
const items = await store.query(gql, params); // an invalid plan throws before executionThree properties make this safe to put behind a model:
Design notes, including the prompt/validate loop: https://coenddt.github.io/nodejs-store/use-cases/02-ai-data-qa-agent.html |
0 replies
Answer selected by
coenddt
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Planning is a pure function — GQL + params in, MongoDB command JSON out — so a model's output can be compiled, validated and rejected before anything touches a database.
Three properties make this safe to put behind a model:
@key, so there is no string-concatenation surface to inject into.