from __future__ import annotations import pytest from hub_core.migrations.roles import migration_role_statement def test_migration_role_is_quoted_and_validated() -> None: assert migration_role_statement("hub_runtime_owner") == 'SET ROLE "hub_runtime_owner"' assert migration_role_statement(None) is None with pytest.raises(ValueError, match="safe PostgreSQL role"): migration_role_statement('owner"; DROP SCHEMA public; --')