Classify inspects a SQL statement and reports whether it is DuckDB secret DDL. It is deliberately conservative: anything it cannot confidently parse as secret DDL classifies as KindNone, which makes the caller fall back to today's plain passthrough behavior. Multi-statement strings classify with Mul
(query string)
| 79 | // MultiStatement set so callers can reject (not silently drop) persistent |
| 80 | // variants. |
| 81 | func Classify(query string) Statement { |
| 82 | st, _, ok := parseSecretDDLHead(query) |
| 83 | if !ok { |
| 84 | return Statement{} |
| 85 | } |
| 86 | st.MultiStatement = hasTrailingStatement(query) |
| 87 | return st |
| 88 | } |
| 89 | |
| 90 | // ContainsPersistentSecretDDL reports whether any top-level statement in query |
| 91 | // is CREATE/DROP PERSISTENT SECRET. Unlike Classify (which inspects only the |