3 ms·
Vulnerable to SQL injection since it’s wrapping string args with single. https://github.com/dmagda/pg-compute-node/blob/main/compute/pg_compute.js#L208 https://
by sa46 3y ago
Vulnerable to SQL injection since it’s wrapping string args with single. https://github.com/dmagda/pg-compute-node/blob/main/compute/pg_compute.js#L208 https://github.com/dmagda/pg-compute-node/blob/main/compute/...
Personally, I’d prefer to create plv8 functions out of band (in a migration) and call them explicitly using a normal DB connection. Much less to go wrong.
- magden 3y agoNice, thanks for catching the issue! https://github.com/dmagda/pg-compute-node/issues/5 https://github.com/dmagda/pg-compute-node/issues/5 This extension is primaraly for those who avoid using database functions at all because of not-the-best dev experience. Once your plv8 function is ready & tested, then it's totally fine to create it once and execute using a DB driver. However, while in development you might need to change the function implementation several times (or you might need to update it after going to prod) and, personally, it's easier to do this from within your IDE. Anyway, those who prefer create functions manually can take advantage of the MANUAL deployment mode: https://github.com/dmagda/pg-compute-node/blob/main/compute/deployment.js#L39 https://github.com/dmagda/pg-compute-node/blob/main/compute/...
- chatmasta 3y agoYou might also consider hooking into the TypeScript compiler (or just using basic codegen) and outputting .sql files containing the migration scripts.