Re: PG 9.0 and standard_conforming_strings

Поиск
Список
Период
Сортировка
От Robert Haas
Тема Re: PG 9.0 and standard_conforming_strings
Дата
Msg-id 603c8f071002031816l1262ba1bne30e0fedbb4b1744@mail.gmail.com
обсуждение исходный текст
Ответ на Re: PG 9.0 and standard_conforming_strings  (Andrew Dunstan <andrew@dunslane.net>)
Ответы Re: PG 9.0 and standard_conforming_strings  ("David E. Wheeler" <david@kineticode.com>)
Re: PG 9.0 and standard_conforming_strings  (Andrew Dunstan <andrew@dunslane.net>)
Список pgsql-hackers
On Wed, Feb 3, 2010 at 5:57 PM, Andrew Dunstan <andrew@dunslane.net> wrote:
> marcin mank wrote:
>> A certain prominent web framework has a nasty SQL injection bug when
>> PG is configured with SCS. This bug is not present without SCS
>> (details per email for interested PG hackers). I say, hold it off.
>
> Any web framework that interpolates user supplied values into SQL rather
> than using placeholders is broken from the get go, IMNSHO. I'm not saying
> that there aren't reasons to hold up moving to SCS, but this isn't one of
> them.

That seems more than slightly harsh.  I've certainly come across
situations where interpolating values (with proper quoting of course)
made more sense than using placeholders.  YMMV, of course.

...Robert


В списке pgsql-hackers по дате отправления:

Предыдущее
От: Robert Haas
Дата:
Сообщение: Re: Add on_trusted_init and on_untrusted_init to plperl UPDATED [PATCH]
Следующее
От: Robert Haas
Дата:
Сообщение: Re: [CFReview] Red-Black Tree