On 01/10/2026 01:14, Alex Liapychev wrote:
>
> My personal view is that adding this functionality carries more risks
> than leaving it out. Although the code is relatively small and appears
> to work correctly, I would not merge it into the codebase.
You mean the multiple tables scenario or the whole patch?
> An example of how this functionality could be used maliciously:
>
> * A workflow creates a new table from several template tables in
> response to an event.
Can you elaborate more on this scenario? I'm afraid I didn't get your
point here. Thanks!
> * An adversarial user with sufficient database access adds one comment
> to each of two template tables. The combined size of these comments
> exceeds |MaxAllocSize|, causing the automation to fail unexpectedly.
An "adversarial" user with enough privileges can do many things break
it, like renaming a column causing a conflict. I see this large comment
scenario as purely theoretical -- at least I fail to see any practical
use case ever exhausting this limit.
Thanks!
Best, Jim