Skip to content

Resource embedding in the query instead of in the URL #3174

Discussion options

You must be logged in to vote

I was more so thinking about creating a function that takes in parameters and does more complicated things, like the things mentioned as potentially unsafe here.

You are creating more problems than you are solving when doing this. You wanted to write your own queries, because of security concerns:

With open source software, this ability to add and execute all sorts of functions and joins and operators and so on can open up the doors to finding potential exploitations. It seems very difficult to foresee what combination of functions and operators might lead to a vulnerability in some situation.

This is just not how it works. Once you write dynamic SQL, you are far more likely to make a…

Replies: 2 comments 7 replies

Comment options

You must be logged in to vote
4 replies
@BorislavZlatanov
Comment options

@rotty3000
Comment options

@rotty3000
Comment options

@BorislavZlatanov
Comment options

Comment options

You must be logged in to vote
3 replies
@BorislavZlatanov
Comment options

@wolfgangwalther
Comment options

Answer selected by wolfgangwalther
@BorislavZlatanov
Comment options

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
3 participants