+19
-2
@@ -2,9 +2,17 @@
|
||||
|
||||
Query Tools is a GPL-3.0-or-later, local-first workbench for bounded JSON, CSV,
|
||||
NDJSON and static XML. It provides an intentionally small SQL-like row language
|
||||
and JSONPath-like value language, result table/tree/JSON views, explain plans,
|
||||
and JSONPath-like value language, parsed SQL/path syntax trees, result
|
||||
table/tree/JSON views, explain plans,
|
||||
local saved queries, and JSON/CSV/NDJSON export. No input is uploaded and no
|
||||
query is evaluated as code.
|
||||
query is evaluated as application JavaScript.
|
||||
|
||||
CSV import has explicit `none`, `safe`, and `aggressive` inference modes and
|
||||
retains every raw cell beside inferred-value evidence. JSON import records raw
|
||||
unsafe-integer and precision-risk number lexemes. A separately selected
|
||||
DuckDB-WASM mode runs bounded, read-only `SELECT` queries in a disposable local
|
||||
worker using same-origin bundled MVP WASM assets; external access and automatic
|
||||
extension loading/installing are disabled.
|
||||
|
||||
SQL subset: `SELECT`, AND-connected `WHERE` comparisons/`CONTAINS`, `GROUP BY`,
|
||||
`COUNT`, `SUM`, `AVG`, `MIN`, `MAX`, `ORDER BY`, and `LIMIT`. Path subset:
|
||||
@@ -13,6 +21,15 @@ not compatibility with full SQL, JSONPath, or JMESPath.
|
||||
|
||||
Limits: 2 MiB source, 10,000 rows/path values, 200 fields, 200,000 structured
|
||||
nodes, depth 32, and 20,000 query characters. XML DTD/entities are rejected.
|
||||
DuckDB mode accepts at most 10,000 rows, returns at most 1,000 rows, uses a 128
|
||||
MiB database memory limit, and has a 30-second startup ceiling followed by a
|
||||
ten-second query deadline. It is not a database connection and does not expose
|
||||
files, network resources, extensions, DDL, DML, `COPY`, or `PRAGMA`.
|
||||
|
||||
Static hosting must serve `.wasm` files as `application/wasm`, cache hashed
|
||||
assets immutably, permit `'wasm-unsafe-eval'` for same-origin scripts, and allow
|
||||
same-origin/blob workers while retaining `connect-src 'self'`. The production
|
||||
browser test verifies those headers against the locally bundled DuckDB asset.
|
||||
|
||||
Run `npm ci`, then `npm run check`, `npm run test:browser`, and
|
||||
`npm run package:release -- --force`. Copyright © 2026 Albrecht Degering.
|
||||
|
||||
Reference in New Issue
Block a user