Have an optional upgrade path (controlled by a setting, off by default) where if a signed ?sql= string appears to be a base64 encoded JSON object with a valid signature we decode that and redirect to the new-style raw SQL URLs
Originally posted by @simonw in #45 (comment)