Running Queries Safely

By default the library trusts its caller: the Rust API and the plain script::eval* helpers allow everything and run without limits beyond the safe script defaults. A host that runs queries it did not write (a web service, a plugin system, an AI agent) restricts them on three levels:

  • Permissions decide what a query may do: read or write data, change the schema, read files, set administrative options. A ready-made AccessPolicy (for example read_only()) or your own Authorizer checks the plan once, before it runs.
  • Limits decide how much it may use: script operations, traversers, materialized bytes, string sizes, nesting depth, a memory budget.
  • Time bounds how long it may run: evaluationTimeout, loop limits, and a cancel token that stops a running query from another thread.

A host sets the defaults and can lock them, so a query cannot raise its own limits with g.with(...). Every refused or stopped query is rolled back.

PageWhat it covers
Permissionsrequests, AccessPolicy, writing an authorizer, file roots
Resource Limitsscript and traversal limits, the memory budget, the defaults of each front end
Query Limitstimeouts and loop limits
Execution Options Referenceevery g.with() key and how a host locks it