backendenhancementgood first issue
Metriche repository
- Star
- (0 stelle)
- Metriche merge PR
- (Metriche PR in attesa)
Descrizione
Use prepared statements to guard against sql injection. Good call @tzinckgraf, thanks for bringing this up! I assigned you but feel free to unassign yourself if you'd rather have someone else work on it.
TODO for this issue: check queries to make sure they are PreparedStatements
https://vitaly-t.github.io/pg-promise/PreparedStatement.html
In our code prepared statements can be formatted like this. Note, name must be unique.
const query = {
name: 'find-source',
text: 'SELECT * FROM sources WHERE id_source_name = $1',
values: idSourceName,
};