3 ms·
Our New Observability Platform for 100B Logs
- gschier 3y agoHey, OP here! We just spent the past 8+ months rebuilding our DIY logging stack on top of ClickHouse. Happy to answer any questions!
- maxwellg 3y agoNice launch! The SQL snippet shared [1] gives me the heebie jeebies. If any one of those where clauses contains user-generated data, that's ripe for a SQL injection vulnerability. `fmt.Sprintf` and SQL almost never belong together. 1 - https://blog.railway.app/_next/image?url=https%3A%2F%2Fres.cloudinary.com%2Frailway%2Fimage%2Fupload%2Fv1695955208%2Fsql-query_p1bk31.png&w=3840&q=75 https://blog.railway.app/_next/image?url=https%3A%2F%2Fres.c...
- gschier 3y agoDon't worry, the generated "whereClauses" also contain replacement markers (values contained in "params") so everything gets escaped correctly.