5 ms·
I like it very much; both the code and interface seem clean and lightweight. You should use mysqli prepared statements though, after a quick glance over the co
by roeme 13y ago
I like it very much; both the code and interface seem clean and lightweight.
You should use mysqli prepared statements though, after a quick glance over the code I can't quite shake the feeling that there might be some sql injections lurking.
- electerious 13y agoAll calls to the API are going through the api.php where every $_POST gets escaped. I'm not an expert when it comes to SQL injection, but I think this should prevent it. See line 61 in php/api.php. It would be great to know if this actually helps or not.
- stefs 13y agoi haven't looked at the code, but you really should switch to prepared statements. they make your code cleaner and more secure (and maybe faster, but that's pretty negligible in this case). have a look at PDO.
- electerious 13y agoI will. Thanks for the notice!
- roeme 13y agoHaving read your code and quickly brushing up the little bits of PHP knowledge from years ago, I'd say it helps only a little. mysqli_real_escape_string alone doesn't protect you completely from sql injection attacks, it just makes it harder - see the second answer at http://stackoverflow.com/questions/5741187/sql-injection-that-gets-around-mysql-real-escape-string http://stackoverflow.com/questions/5741187/sql-injection-tha... for an example. Also, the homegrown $albumID validation allows bad payload to reach mysqli_real_escape_string().
- electerious 13y agoThanks! Good to know.