English · 한국어
Redrob Query is a JVM-free, AI-assisted database workspace built with Rust 1.94, Tauri 2, React 19, and TypeScript. It is a desktop workspace for PostgreSQL, MySQL, SQLite, and MongoDB that reads by default and edits only where you allow it, plus an interactive browser demo backed only by deterministic in-memory sample data.
The workflow is informed by DBeaver Community, but Redrob Query is a clean implementation. It includes no DBeaver source code or branding and no Eclipse RCP, OSGi, JDBC, Java, or JVM runtime.
| Area | Capability |
|---|---|
| Profiles | Create, test, edit, connect, disconnect, and remove user profiles; built-in profiles are immutable |
| PostgreSQL | Identity-verifying TLS, metadata, bounded SQL reads, native scalar decoding, reviewed edits |
| MySQL | Identity-verifying TLS, metadata, bounded SQL reads, unsigned/decimal/temporal/BIT decoding, reviewed edits |
| SQLite | File profiles that open read-only (mode=ro) unless edits are allowed, metadata, guarded reads, reviewed edits; native demo uses :memory: |
| MongoDB | Standard/SRV profiles, separate authSource, collections, bounded 25-document field sampling, strict find/aggregate/explain JSON |
| Results | 25/50/100/250-row paging, typed virtualized rows, current-page sort/filter, column visibility, column and row menus, a details panel, execution messages, and visible CSV export |
| Editing | Off per connection until "Allow edits" is ticked. Edit cells, add and delete rows, create a table or add a column; every change is staged, reviewed and applied in one transaction that rolls back unless each statement changes exactly one row. A result that cannot be edited says why |
| Query workspace | Connection-owned SQL/MQL tabs, engine starters, saved queries (Save / Ctrl+S), several read-only statements in one run with a result picker, pinned tables, local desktop restoration, bounded execution history, formatting, and shortcuts |
| Redrob AI | Engine-aware SQL/MQL generation and explanation through model auto |
| Browser demo | Sample PostgreSQL/MySQL/SQLite/Mongo workflows, local AI responses, and atomic in-memory relational edit review |
SQL Server is not supported in this release: it is absent from the connection UI and rejected by both profile and AI validation paths.
Desktop connections are read-only until you tick "Allow edits" on the connection. Even then nothing is written until you review the staged changes and press Apply: cell edits become UPDATE … WHERE <primary key> = ? with bound values, rows are inserted and deleted the same way, and the whole set runs in one transaction that is undone if any statement does not change exactly one row. Only a plain read of one table with a single-column primary key in the result can be edited. Browser-demo edits change a per-profile in-memory fixture; reload discards them.
React 19 + Monaco + TanStack Virtual
│
Zustand workspace state
│ DataBridge
┌─────┴───────────┐
DemoBridge Tauri IPC allowlist
(browser memory) │
redrob-core (Rust)
┌─────────┼──────────┐
SQLx concrete MongoDB Redrob AI
PG/MySQL/SQLite driver HTTPS client
See Architecture, Security, Demo guide, and the DBeaver workflow map.
The browser demo does not connect to a database or Redrob service and does not persist its workspace.
npm ci
npm run devOpen http://127.0.0.1:1420. The demo starts with the connected Acme Warehouse sample profile. It supports deterministic metadata and queries, two result pages at the default 50-row size, local AI responses, CSV export, profile lifecycle simulation, and reviewed in-memory relational edits.
Requirements: Node.js 22.12+ and npm 11+.
- Install Node.js 22.12+, npm 11+, and the platform packages from the Tauri v2 prerequisites guide.
- Install Rust through rustup;
rust-toolchain.tomlpins Rust 1.94.0, rustfmt, and Clippy. - Install dependencies and launch Tauri:
npm ci
npm run tauri devBuild a package for the current host platform with:
npm run tauri buildLinux requires the WebKitGTK 4.1, JavaScriptCoreGTK 4.1, libsoup 3, and librsvg development metadata expected by Tauri. Frontend production builds and all redrob-core checks run without those packages; only npm run tauri build needs them.
src-tauri/icons/ holds standard Tauri PNG, ICNS, ICO, iOS, and Android icons. Every PNG must be RGBA — tauri::generate_context! panics at compile time on anything else — and npm run release:check asserts it.
Signed installers are produced only by the Signed desktop release workflow, which a pushed vMAJOR.MINOR.PATCH tag starts. It builds Linux x64, macOS Intel, macOS Apple Silicon, and Windows x64, signs the updater bundles, notarizes the macOS builds, and uploads everything plus latest.json to a draft GitHub Release. Publishing that draft is the release: GitHub Releases is the update channel, so releases/latest/download/latest.json only ever serves a version a human published. Missing credentials stop the release rather than publishing unsigned artifacts.
Desktop mode stores up to 30 open query tabs and 50 successful first-page history entries in versioned renderer local storage. Only query text and tab/history metadata are stored, never result rows, database credentials, or AI prompts. Empty tab drafts are valid and restored; execution history retains only nonempty queries that completed successfully on the first page. Query text is plaintext and may itself contain sensitive literals, so the history menu provides Stop saving & clear local data. That opt-out is stored separately and remains disabled across restarts until the user explicitly re-enables saving. Invalid, duplicate, engine-incompatible, oversized, or corrupt entries are rejected; storage failure is shown instead of claiming a successful save.
Browser-demo tabs and history remain in memory for the current page session only. Selecting, restoring, or loading desktop state never auto-connects or auto-runs a query.
npm run release:check
npm run typecheck
npm test
npm run test:coverage
npm run build
npm audit --audit-level=low
cargo fmt --all -- --check
cargo clippy --locked -p redrob-core --all-targets --all-features -- -D warnings
cargo test --locked -p redrob-core --all-features
cargo audit --file Cargo.locknpm run release:check verifies npm, Cargo, Tauri, lockfile, Rust toolchain, product name, bundle identifier, window label, and development URL metadata. Coverage has global regression floors of 85% statements/lines, 75% branches, and 65% functions.
The default Rust core run executes hermetic tests and reports three external connector tests as ignored. It is not live-server evidence. To run the ignored gates, export disposable service URLs and explicitly opt in:
export REDROB_TEST_POSTGRES_URL='postgresql://…'
export REDROB_TEST_MYSQL_URL='mysql://…'
export REDROB_TEST_MONGO_URL='mongodb://…'
export REDROB_TEST_MONGO_DATABASE='redrob_test' # optional
cargo test --locked -p redrob-core --all-features -- --ignoredAn explicitly run live test fails when its required URL is absent. Use non-production credentials; the Mongo gate creates and drops only a UUID-named collection. Rust does not automatically load .env files.
npm run check also includes workspace-wide Rust checks and therefore requires native Tauri system packages on Linux.
- Non-secret profile metadata is stored in plaintext
connections.json; passwords and the Redrob key use the OS keyring. - A secret-free fsynced journal, staged keyring entry, and exclusive profile lock make updates recoverable and fail closed under unsafe recovery or concurrent ownership.
- Typed queries are reads only: each run accepts read-only statements (several only when every one is read-only, each executed on its own), with PostgreSQL/MySQL read-only transactions and a fail-closed SQLite PRAGMA allowlist. Writes happen only through reviewed edits on a connection that allows them.
- Mongo requests are strict and bounded; aggregate
$outand$mergeare rejected recursively. Metadata merges top-level type/presence/nullability hints from at most 25 documents and is not a complete schema. - Enabled PostgreSQL/MySQL TLS verifies certificate identity with public trust roots. Private/self-signed CA configuration is unavailable.
- Desktop AI sends the prompt and optional active query to Redrob. Result rows and credentials are not attached, but sensitive literals manually included in either text are transmitted.
Read the complete security model and limitations.
- No free-form write SQL: changes go through the reviewed edit and table forms only. Tables need a single-column primary key to be edited; MongoDB results are not editable.
- Paging is server/bridge bounded, while sorting and filtering apply only to the currently loaded page.
- No custom CA/client-certificate UI, SSH tunnel, cloud-auth plugin, script runner, ER diagram, administration suite, data-transfer pipeline, compare/migration tooling, driver marketplace, or SQL Server connector.
- Mongo sampled metadata is a bounded hint, not authoritative collection schema inference.
- External PostgreSQL/MySQL/Mongo and Redrob API integration require user-supplied services/credentials and are not exercised by the browser demo.
Use Redrob settings in the desktop app to store a key in the OS keyring. For development, a nonempty REDROB_API_KEY takes precedence over the saved key. The native client calls:
https://console.redrob.ai/api/backend/v1/chat/completions
The provider request uses model auto. Browser-demo AI is local and deterministic; an entered demo key is not retained or sent.
Redrob Query is licensed under the GNU General Public License, version 3 or later. It was Apache-2.0 until it began incorporating Beekeeper Studio Community Edition source, which is GPL-3.0-or-later; the stronger copyleft travels with the code. See NOTICE for attribution and for the trademark reservation. Third-party components remain subject to their own licenses.