waterthetrees/wtt_server
Check queries for prepared statements
Aberta
#136 aberto em 20 de mar. de 2023
backendenhancementgood first issue
Métricas do repositório
- Stars
- (0 estrela)
- Métricas de merge de PR
- (Nenhuma PRs mesclada em 30d)
Description
Use prepared statements to guard against sql injection. Good call @tzinckgraf, thanks for bringing this up! I assigned you but feel free to unassign yourself if you'd rather have someone else work on it.
TODO for this issue: check queries to make sure they are PreparedStatements
https://vitaly-t.github.io/pg-promise/PreparedStatement.html
In our code prepared statements can be formatted like this. Note, name must be unique.
const query = {
name: 'find-source',
text: 'SELECT * FROM sources WHERE id_source_name = $1',
values: idSourceName,
};