@youTellMe to Programmer HumorEnglish • 4 days agoEveryday we stray further from industry standardsimagemessage-square24arrow-up1187arrow-down11
arrow-up1186arrow-down1imageEveryday we stray further from industry standards@youTellMe to Programmer HumorEnglish • 4 days agomessage-square24
minus-square@surewhynotlemlinkEnglish1•3 days agoIf that’s a pass through, that’s bad. If that’s used for authentication, authorization, credential limiting, or rate limiting, then sure.
minus-square@[email protected]linkfedilinkEnglish3•3 days agoThere is no context in this world validating this level of unsanitized SQL. Even for internal use this is bad, since it bypasses the auth of server and dbms.
If that’s a pass through, that’s bad.
If that’s used for authentication, authorization, credential limiting, or rate limiting, then sure.
There is no context in this world validating this level of unsanitized SQL. Even for internal use this is bad, since it bypasses the auth of server and dbms.
That is a very good point.