Recern Workspace · Documentation

Safe Mode and the console

Each PostgreSQL and Redis connection has a Console view for running your own SQL or commands. Safe Mode decides what the console may run.

Safe Mode is on for production connections and marked in the window header and on the dashboard. You can turn it on for any connection in its settings.

PostgreSQL

Without Safe Mode, the console runs what you type, including several statements at once.

In Safe Mode:

  • The console runs one statement at a time. Text with several statements is refused before anything runs.
  • The statement runs inside BEGIN READ ONLY, and the transaction is always rolled back. Whatever the statement does, nothing is committed.

In both modes the console shows up to 1,000 rows per statement and stops the query after that. Cancel stops a running statement.

Redis, Valkey and Dragonfly

Some commands are never run by the console, in any mode, because they never return or change what the console connection is: SUBSCRIBE, PSUBSCRIBE, SSUBSCRIBE, MONITOR, SYNC, PSYNC, SELECT, QUIT, RESET and HELLO. To use another database, edit the connection.

In Safe Mode, Recern asks the server about each command (COMMAND INFO) and runs it only if the server marks it read-only and not dangerous. A short list of harmless diagnostics is always allowed, such as INFO, PING, CLIENT LIST, CONFIG GET, SLOWLOG GET and MEMORY USAGE.

So GET and HGETALL run, while SET, DEL and FLUSHALL are refused, and so is KEYS, which reads but can block a large server.