mirror of
https://github.com/simonw/datasette.git
synced 2026-09-28 12:54:10 +02:00
Clearly document relationship between execute-sql and facets
Refs GHSA-5fff-xcm9-q6vh Co-authored-by: Alex Garcia <15178711+asg017@users.noreply.github.com>
This commit is contained in:
parent
f6d0f9bd38
commit
6473a7ecb0
3 changed files with 8 additions and 0 deletions
|
|
@ -71,6 +71,8 @@ Should users be able to execute arbitrary SQL queries by default?
|
|||
|
||||
Setting this to ``off`` causes permission checks for :ref:`actions_execute_sql` to fail by default.
|
||||
|
||||
This setting controls the ability to submit arbitrary SQL. It does not disable structured table-browsing features that use SQL generated by Datasette, such as sorting, column filters and :ref:`facets`. Use :ref:`setting_allow_facet` to control whether users can request facets.
|
||||
|
||||
::
|
||||
|
||||
datasette mydatabase.db --setting default_allow_sql off
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue