Repository navigation
Releases: monsama/nobs-sql-editor-powershell
Release list
v1.6.3
Verify your download
This script is not code-signed. Compare what you downloaded against the SHA-256 below:
0f81bd5f2315660431a2baee02a6b6dc285485bc3b96bd39b3d852ae4495afc6 NOBSSQL.ps1
PowerShell: Get-FileHash .\NOBSSQL.ps1 -Algorithm SHA256
See CODE_SIGNING.md for what this does and does not prove.
What's changed
- Set NULL on picked cells counts and changes only the cells that can hold NULL: picked across NOT NULL and nullable columns, the menu reads "Set 2 of 6 picked cells to NULL" instead of offering all six and skipping four.
- Set empty is no longer offered for columns with no empty value - numbers, dates and times, BIT, JSON, spatial, INET, UUID, generated columns and ENUMs without an empty member - where strict mode refuses it and non-strict mode quietly stores 0 or a zero date. Picked cells read "Set 1 of 3 picked cells to empty" the same way.
Full Changelog: v1.6.2...v1.6.3
v1.6.2
Verify your download
This script is not code-signed. Compare what you downloaded against the SHA-256 below:
667299d103fb459cd58c78f1bb469be5a9a53a2c95a17303e7adcf408dc8b1ca NOBSSQL.ps1
PowerShell: Get-FileHash .\NOBSSQL.ps1 -Algorithm SHA256
See CODE_SIGNING.md for what this does and does not prove.
What's changed
- History, Library, Transaction log, Process list and Inspect open bigger, and every window keeps the size and place you give it - after a restart too. Default appearance in Settings resets them
- The welcome screen says what the app is: a fast, lightweight client for MySQL and MariaDB
- The top bar no longer shows the app's name, leaving more room for the connection controls
- A query stopped by the connection's time limit on MariaDB 12 is now explained as such
Full Changelog: v1.6.1...v1.6.2
v1.6.1
Verify your download
This script is not code-signed. Compare what you downloaded against the SHA-256 below:
a75dedd53beee1260ef15ba9bbe503f420a50ef2c5ad1393012570ed109be81e NOBSSQL.ps1
PowerShell: Get-FileHash .\NOBSSQL.ps1 -Algorithm SHA256
See CODE_SIGNING.md for what this does and does not prove.
What's changed
- Costliest queries: filter by database, reset the figures, and click a query to open its plan
- A query stopped by the connection's time limit now says so, and which limit it was
- Fixes for two races
- Top bar: even spacing between every button and separator
Full Changelog: v1.6.0...v1.6.1
v1.6.0
Verify your download
This script is not code-signed. Compare what you downloaded against the SHA-256 below:
408e2d0be0330cfb24d97ee9e886c3578012c9a630edc0bff08802b55d8c880b NOBSSQL.ps1
PowerShell: Get-FileHash .\NOBSSQL.ps1 -Algorithm SHA256
See CODE_SIGNING.md for what this does and does not prove.
What's Changed
- Grid: non-text bytes as hex; invisible characters badged; runs collapsed by @monsama in #34
- Grid: line breaks, tabs and edge spaces drawn; Hex tab byte view by @monsama in #35
- Grid: drag past the edge keeps picking under an overlay and before rows are drawn by @monsama in #36
Full Changelog: v1.5.3...v1.6.0
v1.5.3
What's new in 1.5.3
Fixes
- Run at the cursor ran the next line's statement. With the cursor right after a statement's
;- where typing it leaves the cursor - Ctrl+Enter ran the statement on the line below instead, aDELETEas readily as aSELECT; also with spaces or a comment after the;. Explain did the same. It now runs the statement the;ends. - Editing the saved connection you are on no longer breaks it. Renaming it, or turning read-only on or off, left the open connection unable to switch databases (
Access denied ... (using password: NO)) until you reconnected. It now carries on, and reconnects by itself when the address, user, SSL or SSH settings change. - Commit showed nothing to commit over a real write. With auto-commit off, a run such as
SELECT '#'; DELETE FROM torSELECT 5--1; DELETE FROM twas taken for a read, so Commit stayed dark over an uncommitted change. A#or--inside a string, and/*! ... */, are now read as the server reads them, and a locking read (FOR UPDATE,FOR SHARE) counts too. - Selecting cells with the mouse: dragging to the edge of the results now scrolls them and keeps selecting, as in a spreadsheet. A drag from a cell no longer selects page text instead - for example from the last row straight down, which used to select values and window text rather than cells.
- Markdown export: a cell with a lone carriage return no longer breaks its table row.
ER diagram
- Each column shows its type, with PK, FK and UQ marks; a type in italics takes NULL. The header shows the table's estimated rows.
- Tables are laid out by relationship: each to the right of the tables it refers to, near the ones it is linked with.
- Lines run at right angles to the exact rows a key joins, with crow's-foot ends (one, or none-or-one where the key takes NULL), and go around tables rather than under them. Point at a line to see its foreign key and the two rows light up.
- Fit to window, Export SVG next to Export PNG, and Ctrl + mouse wheel zooms toward the pointer. Exports match the theme.
Settings
- Text size for the editor and for the results, an interface zoom, and fonts for code, results and the interface - only fonts installed on the computer are offered.
- Default appearance → Restore defaults replaces the separate layout and font resets: one button puts the layout (including the Databases / Objects divider, which the old reset missed), theme, fonts, text sizes, zoom and notification duration back.
- Clear all app data now clears everything the app keeps, as it says - layout, appearance and all other preferences too, and the zoom - keeping only the client tool paths. It used to leave most preferences behind.
- Clear overview cache is available while disconnected; its button used to disappear.
- Settings are worded more plainly throughout.
Grid and editor
- Copy picked cells and paste them in the same shape, gaps included; set several picked cells to NULL; export the rows of picked cells.
- Copy as INSERT statements, from the right-click menu and the Copy button.
- Edit row (form) reworked; double-clicking a value opens its editor. Ctrl and Shift now include the cell you are on.
- Right-click menus laid out the same way everywhere, exports in a submenu.
- Quick filters belong to the query they were made for, and go when another query is run.
- F6 moves between the editor and the results, F9 runs, Ctrl+Shift+F formats, F1 shows the keyboard shortcuts - now one line each, in three columns.
Connections
- The connection dialog is reorganised into sections, shows only what applies, and has Test connection.
- New connection, then Esc or New again, goes back to the connection you were on.
- Deleting the saved connection you are on asks first, then disconnects.
Verify your download
This script is not code-signed. Compare what you downloaded against the SHA-256 below:
122484700adaf52273d2d888f276d4669a9804af07956c04a368f62a5d13a272 NOBSSQL.ps1
PowerShell: Get-FileHash .\NOBSSQL.ps1 -Algorithm SHA256
See CODE_SIGNING.md for what this does and does not prove.
Full Changelog: v1.5.2...v1.5.3
v1.5.2
What's new in 1.5.2
Security: a saved password never reaches the app's page. Until now, picking a saved connection handed its password - and its SSH password - to the page, which sent it with every request. The page now only names the saved connection, and the password is filled in behind it: only for the host, port and user it was saved for, and with that connection's own SSL settings. A script that got into the page could otherwise have read every saved password, or sent one to another server under the saved connection's name.
What this changes for you:
- The password box stays empty for a saved connection; the key icon still shows that one is saved.
- In Save, Edit and Clone connection, leave the password box empty to keep the saved password.
- A saved connection pointed at another host, port or user has its password typed again - a saved password is never carried over to a different address.
This completes the security review of 1.5.1.
Verify your download
This script is not code-signed. Compare what you downloaded against the SHA-256 below:
3183e1398a5301cb07101ce6230da5fc56f8713f43dba5f651641ff5876bb327 NOBSSQL.ps1
PowerShell: Get-FileHash .\NOBSSQL.ps1 -Algorithm SHA256
See CODE_SIGNING.md for what this does and does not prove.
Full Changelog: v1.5.1...v1.5.2
v1.5.1
What's new in 1.5.1
A security release. A review of the whole app found a number of ways a file, a web page or another program on the computer could get the app to do more than it should. All of them are fixed. Please update.
The local server
- Any program on the computer could use the app's server: the check of the token let a request with an empty list for a token through, and the token was in the page the server hands to anyone who asks. The token is now checked strictly, is no longer in the page (it comes in the address the app window opens with), and the server refuses requests from other web pages and anything but the app's own kind of request.
- Every response now tells the browser not to show the app inside another site and not to load anything from elsewhere.
- Settings could be made to run any program as a "client tool". A tool now has to be mysql or mysqldump, an .exe, on this computer, and Settings checks that when it saves as well.
Action needed for PAM / LDAP accounts. MySQL's client no longer sends a password as typed (PAM or LDAP) over SSL required on its own: that mode does not check the server's certificate, so someone in between could pose as the server and read it. Use verify-ca or verify, or - on a network you trust - tick the new PAM / LDAP sign-in box in the saved connection.
Import
- A dump file could run commands on your computer. MySQL's command-line client carries out
system <command>andtee <file>found in a file it loads; a dump someone sends you could hold them. Import now runs the client in binary mode, where it refuses every client command. Raw NUL bytes go through as well, so the "Binary mode" box is gone - it is always on. - A database or table name that starts with
-could be read by the client tools as an option. Names are now passed so that they are always names.
Read-only / safe mode
- Several statements that write got through:
EXPLAIN ANALYZEof a multi-table UPDATE or DELETE,SET GLOBALorPERSISTafter another assignment,SET RESOURCE GROUP,INTO OUTFILEafter an earlierINTO @var, a client command inside an optimizer hint (/*+ ... */), and names or strings with backslashes read the wrong way. All are refused now. - A connection saved as read-only stays read-only in the server, whatever the page asks - unless another saved connection to the same account is not read-only.
And
- Temporary files that hold a password are private to you, removed after use, and cleaned up at the next start if the app was killed. The SSH password goes to ssh through such a file, not its environment.
- The command-line tools refuse
LOAD DATA LOCAL, so a server cannot ask them for a file. - A password in SQL that the app logs, shows in a message or keeps with your open tabs is written as
'***'. - WAMP and XAMPP folders are no longer searched for client tools: any user of the computer can write to them. Pick their tools in Settings.
- Downloads: a changed MySQL download address has to be https, and the update notice opens only this project's release page.
- A saved transaction's Apply writes values for that session's own
sql_mode. - Table and column names with quotes, line breaks or names like
constructorno longer break Compare, the ERD, Export or Import.
The README has a new Security notes section on what read-only, import, SSL and SSH tunnels do and do not protect against.
Verify your download
This script is not code-signed. Compare what you downloaded against the SHA-256 below:
6ce969c408ffaa009e46402c60ce9001881e5b96a7cb7940f2504c48f9f306bc NOBSSQL.ps1
PowerShell: Get-FileHash .\NOBSSQL.ps1 -Algorithm SHA256
See CODE_SIGNING.md for what this does and does not prove.
Full Changelog: v1.5.0...v1.5.1
v1.5.0
What's new in 1.5.0
One interface. Every window was reviewed and brought into one style: the same headings, cards, buttons, corners, colours and font throughout, the main action of each window in the accent colour, and one word for one thing - "database" rather than "schema", "account" for users - with window titles that match the buttons that open them. Buttons, inputs and lists now use the app's font instead of the browser's Arial, and every field in a window is as tall as its buttons.
Security: an export on SSL "required" is encrypted or does not run. MariaDB's dump tool has no way to refuse a server without TLS, and dumped in plaintext from one. The export now reads the server's certificate first and pins the dump to it; the earlier check through mysql.exe just before the export is replaced.
Settings
- Pages: Client tools, General and Local data.
- Save checks each client-tool path before it keeps it: the file has to exist, be the tool its box asks for (mysql or mariadb, mysqldump or mariadb-dump), and start as a MySQL or MariaDB client. It used to store any path, including another program's.
- Each path says what it comes to, and the version found, in a chip beside it.
- Local data shows where the settings and the downloaded tools are kept, with Open folder buttons.
- Downloaded client tools now go to
%LOCALAPPDATA%\NOBSSQL\bininstead of the roaming AppData, which networks with roaming profiles copy at every sign-in and sign-out. Tools downloaded before keep working from their saved paths.
Users and privileges
- A click in the account list selected the account but left Privileges, Roles, Account and Drop greyed out. Every action is now in the picked account's panel and works from a click.
- Each account at a glance: how it signs in, its privileges as a table of where they apply and whether it may pass them on, and its roles - each with its own Edit. The GRANT statements are still there, folded.
- Rename an account or its host.
- Who has access is a window of its own: pick the database, filter the accounts, see where each may act; a click opens the account.
- The role checkboxes say what ticking them does.
Inspect is a window of its own: a table's details and sizes, its indexes with their columns in order, its foreign keys, and the tables that point at it - each a click away. Indexes of several columns used to be listed once per column.
Overview. The server's figures as cards, with what is worth a look marked and counted; your databases before the server's own. Clicking a database used to mark every database whose name contained it.
Right-click menus offer what fits
- The server's own databases offer nothing that creates or drops; information_schema and performance_schema only what reads them.
- A table's upkeep sits in one Maintenance menu, and Repair shows only for the engines that support it (MyISAM, Aria, CSV, Archive).
- With several cells or rows picked, the commands are for all of them; "Delete N selected rows" is new.
- On a read-only connection a cell offers View value and nothing that edits.
And
- The file browser: type or paste a path, see sizes and dates, filter by name, move with the arrow keys; each kind of pick opens where the last one was made, and a folder list starts at Desktop, Documents and Downloads.
- The connection box keeps its width when switching connections, so the bar no longer jumps; the arrow beside it reconnects the open connection or switches to the picked one. The green status pill is the Disconnect button.
- A result narrower than the window had a horizontal scrollbar for nothing.
- An empty tab loads the database overview by itself.
- Compare and row compare open larger and say what to do before the first run.
- History: a click on a query no longer closes the window; open it with Open or a double-click. Library opens as large as History.
- Picking every cell of a row counts as picking the row; Esc lets picked cells go, and pressed again unticks the rows.
- The SSL modes explain themselves in their tooltips.
Verify your download
This script is not code-signed. Compare what you downloaded against the SHA-256 below:
21bb5030b0625be116b248b59170f8d150e90e1d2876e0278fdf64b7263f4f7d NOBSSQL.ps1
PowerShell: Get-FileHash .\NOBSSQL.ps1 -Algorithm SHA256
See CODE_SIGNING.md for what this does and does not prove.
Full Changelog: v1.4.0...v1.5.0
v1.4.0
What's new in 1.4.0
Security: SSL "required" now always means encrypted. With MariaDB's client tools - which the PowerShell edition uses for everything, and the desktop edition for Export and Import - a connection set to SSL "required" went on unencrypted when the server had no TLS at all. It is now refused, with a message that says the connection was not encrypted. SSL "default" also uses TLS whenever the server offers it; it used to connect in plaintext. If a server really has no TLS, set the connection to "disabled" knowingly. ("required" encrypts but checks no certificate; use "verify" or "verify-ca" to also know who you are talking to.)
Older and newer servers. Every release is now tested against MySQL 5.7, MariaDB 10.2 and MySQL 9.4 as well as current MariaDB and MySQL. What that found is fixed:
- MySQL 5.7: with MySQL 8 or later client tools, text came back in latin1, and characters latin1 cannot hold became "?" - in a data-only export, and in the PowerShell edition's grid. A 5.7 dump no longer imports "with warnings" over a harmless note about NO_AUTO_CREATE_USER.
- MariaDB 10.2: a dump made by a newer MariaDB imports on it. The user editor offers password expiry and locking only where the server has them - Create user used to make the account and then fail half-way - and Create role only where roles exist. Clone copies the grants on 5.7 and 10.2 too.
- MySQL 9: VECTOR columns show as their bytes in hex and save back exactly.
- Compare treats a column named in another case as the same column, and a table too on a server that ignores the case of table names (Windows and macOS) - it used to offer them as missing, and the fix then failed.
PAM sign-in (desktop edition). Accounts that sign in through PAM or LDAP can connect, over an encrypted connection. On MariaDB the server has to ask with pam_use_cleartext_plugin=ON; the connection error says so when it does not.
Editing
- Pick several cells and set them all to NULL or empty from the right-click menu; the change is staged like any other.
- Set NULL is offered only where the column can hold NULL, and the NULL button no longer spills into the cell next to it.
- A grid is editable only when every column really is the table's own; a query with a subquery, a comment or a computed column used to save to the wrong place or cut values short. Generated columns cannot be edited or pasted into.
- Edits, deletes and pastes of many rows go in batches - deleting thousands of picked rows no longer takes two round trips each.
- Editor commands can be undone, Tab indents a selection, and Explain takes the statement at the cursor.
- "Go to referenced row" follows a foreign key into another database and uses all its columns.
Large results. A page of rows also stops at 32 MB, so a table of large BLOBs no longer hangs the app or runs it out of memory; the rest loads as you scroll. The object list stays quick on schemas with thousands of objects.
Schema sync compares indexes, foreign keys, CHECK constraints, ON UPDATE and AUTO_INCREMENT, puts an added column where the source has it, and creates a child table after its parent. A table that differed only in those used to show as the same.
Table designer warns when MySQL will give a TIMESTAMP column an automatic default, keeps a column's CHECK and SRID, reads the primary key in its own order, and no longer writes NOT NULL DEFAULT NULL.
Import and export
- Import reports warnings - a value cut to fit - not only errors.
- A MariaDB dump opens on MySQL's client, and views are restored after the tables they read.
- Leaving out DEFINER changes the definitions only and keeps every byte of the rows.
- A failed dump is kept as
.partialinstead of looking complete; a CSV export says when a value is the NULL marker's own text. - An export to a folder named in another alphabet says why MySQL's mysqldump cannot write there.
Users
- Changing the password of a MariaDB account that signs in more than one way (the usual Linux root) keeps its other ways.
- A database-level grant names the database exactly: "_" and "%" are wildcards there.
- Clone keeps a required client certificate.
Scripts and read-only mode
#and--comments are read as the server reads them: Run at the cursor no longer sends the statements after it, and read-only mode sees a write hidden behind a comment.- A script whose SELECT reads session state (ROW_COUNT(), @variables, temporary tables) runs on one connection.
- Passwords are not kept in the history.
Verify your download
This script is not code-signed. Compare what you downloaded against the SHA-256 below:
6d063b948a71480b0279ca559a0043192fed7583f87cdcd764cde83b885b0121 NOBSSQL.ps1
PowerShell: Get-FileHash .\NOBSSQL.ps1 -Algorithm SHA256
See CODE_SIGNING.md for what this does and does not prove.
What's Changed
Full Changelog: v1.3.19...v1.4.0
v1.3.19
What's new in 1.3.19
A user editor. Users has grown from a list of grants into the place accounts are looked after.
- Privileges... shows what an account or role may do - on the whole server, one database or one table - as boxes, ticked for what it has. Changing them shows the GRANT and REVOKE they become before anything runs. The boxes are the server's own list, so a privilege only MySQL or only MariaDB has shows where it exists. Typing a GRANT or REVOKE by hand is still there, for columns and routines.
- Roles. New > Create role, and Roles... to give an account roles and pick the one active when it signs in - on MySQL and MariaDB alike, though the two keep roles differently.
- Clone makes a new account like the selected one: its sign-in method, settings, grants and roles, under its own name, host and password.
- Account > Settings... - and Create user - set the sign-in method, SSL required or a client certificate, password expiry and the four connection limits. Only what changed is sent, and a password never reaches the log. Lock and Unlock are in the same menu.
- The list has a filter and marks each entry as a role, a system account, locked or password expired; the selected account's details sit over its grants. Who has access... lists everyone with privileges on a database, down to its tables and columns.
- The buttons fit in one row: what acts on the selected account stays grey until there is one.
Export: structure only, or data only. Export asks first what goes in - structure and data, structure only, or data only. Data only leaves out routines, events, triggers and the CREATE and DROP lines, and still writes a file per table. It opens at structure and data every time, so a backup never goes out without its rows because of an earlier choice. The options most exports change stay on show under plain names; the rest fold into Advanced options, each with its mysqldump option in its tooltip.
Import lists its files with their folder and size, each with its own remove button, instead of a box of typed paths. A file added twice is listed once, and the target database offers the server's databases in both editions.
The user transfer script is sound.
- It carries roles: on MariaDB they were lost, with every grant that named them; on MySQL an account with a default role could come before its role and fail.
- It can run again on a server that already has some of the accounts.
- Its first line stops it on the wrong kind of server - a MySQL script on MariaDB or the other way round - before anything is changed.
Smaller things.
- When the query bar is narrow, Run Selection and Explain keep their labels longest; Chart sits with Copy, Wrap and Columns, left of the search box.
- The eye in a password box is centred on it.
- Menus and the database list draw above floating windows however often those have been raised.
Verify your download
This script is not code-signed. Compare what you downloaded against the SHA-256 below:
f887472225582ff1b4f26e9a45f87e577dd16449624294620fff92fdd9c882af NOBSSQL.ps1
PowerShell: Get-FileHash .\NOBSSQL.ps1 -Algorithm SHA256
See CODE_SIGNING.md for what this does and does not prove.
Full Changelog: v1.3.18...v1.3.19