4 ms·
If you're using sprocs to fix SQL injection you're Doing It Wrong.
by bcoates 11y ago
If you're using sprocs to fix SQL injection you're Doing It Wrong.
- jessaustin 11y agoThere are corner cases in which stored procs don't totally protect the foolish, but they fix 95% of the problem. What "Right" solution are you using that eschews stored procedures completely? [EDIT:] Of course if your use case allows you can just get by with a tiny whitelist. Nice work if you can get it.
- sokoloff 11y ago(Fan of sprocs here, but) Parameterized queries can give you the same level of protection from SQL injection as sprocs.
- jessaustin 11y agoHaha I think we mostly agree but I doubt that's what 'bcoates had in mind...
- bcoates 11y agoNo he's right parameterized queries are how you prevent SQL injection (imo, the only correct answer). Doing a stored procedure for an SQL one-liner is just bringing a world of pain.
- jessaustin 11y agoDo you find that all your service endpoints are naturally just a one-liner? I guess tastes differ with respect to schema organization, etc. Sorry for misunderstanding!
- sokoloff 11y agoSprocs give you finer grained access control though (a sproc for which a user has permissions can perform actions that the user can't do directly) as well as being very quick to patch in a prod emergency (useful in the case where you are using a compiled or otherwise slow to deploy language). I've made many a one-line sproc in my day; the overhead at dev time seems minimal by comparison, but that's just my opinion. I can see the other side as well.