3 ms·
The popular pg-promise library for PostgreSQL in NodeJS has a similar issue - for some types of queries ("Formatting Filters") it interpolates parameters itself
by phiresky 5y ago
The popular pg-promise library for PostgreSQL in NodeJS has a similar issue - for some types of queries ("Formatting Filters") it interpolates parameters itself instead of using real parameterized queries.
This is especially bad because it uses it's own escaping function and escaping in PG depends on a server configuration variable (standard_conforming_strings) that the client doesn't know about.
This behavior is barely mentioned in the docs, and the author does not really accept any suggestions or criticism.
- SahAssar 5y agoIs there any reason to not use the pg package? It does promises too, and has been rock solid for me.
- throw_m239339 5y ago> This behavior is barely mentioned in the docs, and the author does not really accept any suggestions or criticism. This is where the programming community has a role to play. When library authors blatantly brush off security issues, it's time to call out that behavior publicly and promote a secure fork. a database library should never have hidden behaviors such as theses. And "magics" such has manually building strings into a query like that s, or parsing a provided query to transform it into something else under the hood, should be turned off by default. This is absolute madness.