-
Notifications
You must be signed in to change notification settings - Fork 4
Open
Labels
backendenhancementNew feature or requestNew feature or requestgood first issueGood for newcomersGood for newcomers
Description
Use prepared statements to guard against sql injection.
Good call @tzinckgraf, thanks for bringing this up! I assigned you but feel free to unassign yourself if you'd rather have someone else work on it.
TODO for this issue: check queries to make sure they are PreparedStatements
https://vitaly-t.github.io/pg-promise/PreparedStatement.html
In our code prepared statements can be formatted like this. Note, name must be unique.
const query = {
name: 'find-source',
text: 'SELECT * FROM sources WHERE id_source_name = $1',
values: idSourceName,
};
Metadata
Metadata
Assignees
Labels
backendenhancementNew feature or requestNew feature or requestgood first issueGood for newcomersGood for newcomers
Type
Projects
Status
Todo