3 ms·
Agreed, write raw SQL, this has never had any security impact whatsoever[1] - Your friendly local pentester [1] - https://en.wikipedia.org/wiki/SQL_injection
by sunbum 7mo ago
Agreed, write raw SQL, this has never had any security impact whatsoever[1]
- Your friendly local pentester
[1] - https://en.wikipedia.org/wiki/SQL_injection https://en.wikipedia.org/wiki/SQL_injection
- christophilus 7mo agoPorsager’s Postgres package does a great job of letting you feel like you’re writing raw sql, but avoids the attack vectors. Anyway, I agree that ORMs are pretty terrible. I like writing SQL or using a lightweight builder like Kysely. Was a huge Dapper fan back in my C# days. There are plenty of reasonable alternatives to ORMs that don’t open you to SQL injection attacks.
- lowsong 7mo agoParameterized queries have been a thing for decades, which mitigate SQL injection attacks.[1] This is true of the examples in the post too, they used this: query = """ SELECT * from tasks WHERE id = $1 AND state = $2 FOR UPDATE SKIP LOCKED """ rec = await self.db.fetchone(query=query, args=[task_id, TaskState.PENDING], connection=connection) [1] https://en.wikipedia.org/wiki/SQL_injection#Parameterized_statements https://en.wikipedia.org/wiki/SQL_injection#Parameterized_st...
- Lockal 7mo agoParameterized queries fail to protect from SQL injection for decades, because database engine developers fail to listen. What could work instead, if any parameter could be safely injected: SELECT $1, $2($3) FROM $4 WHERE $5 $6 $7 GROUP BY $1 ORDER BY $8 $9 but at that point SQL loses its point and turns into MongoDB query language.