4 ms·
I like the general idea, if you want some "insurance", you could also set the database user that the application uses to SELECT only permission. Have you ruled
by notaddicted 14y ago
I like the general idea, if you want some "insurance", you could also set the database user that the application uses to SELECT only permission.
Have you ruled out using a router? (like https://docs.djangoproject.com/en/dev/topics/db/multi-db/#using-routers https://docs.djangoproject.com/en/dev/topics/db/multi-db/#us... )
- craigkerstiens 14y agoI did consider using the router and actually inspecting form data as well, both felt far more convoluted and could result in tougher to bug situations should issues arise. While I'd love to have something more robust and safe this is currently just v0.1 and I generally am looking forward to more conversation around what users see as acceptable.