5 ms·
So, I get it and all that, what are some real world use cases of this and the postgresql equivalent? Who's actually using these things for something other than
by cdine 16y ago
So, I get it and all that, what are some real world use cases of this and the postgresql equivalent? Who's actually using these things for something other than saying how fast they are?
I just hope they aren't being used as public-facing JSON API endpoints and the such, since none of them seem to even consider the case of SQL injection. From a quick glance it doesn't seem that any type of parameterized query or prepared statements are available to even begin helping with that, and the "documentation" examples wouldn't be setting people off on the right foot by even limiting the location paths with strict regex's.
- jbeluch 16y agoThe example seems to use both regex and set_quote_sql_str to prevent sql injection.
- cdine 16y agoInteresting, thanks for the pre-coffee clarification. aka I can't read =] I'm sure people will still mess things up :)
- piotrSikora 16y ago> Who's actually using these things for something other than saying how fast they are? Taobao.com (14th biggest site in the world, 3rd in China - according to Alexa) is using ngx_drizzle + ngx_rds_json in production. Qunar.com is using ngx_postgres + ngx_rds_json.