Lemmy
  • Communities
  • Create Post
  • Create Community
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
youTellMe@lemmy.world to Programmer Humor@lemmy.worldEnglish · 9 months ago

Everyday we stray further from industry standards

lemmy.world

message-square
24
fedilink
190

Everyday we stray further from industry standards

lemmy.world

youTellMe@lemmy.world to Programmer Humor@lemmy.worldEnglish · 9 months ago
message-square
24
fedilink
  • sebsch@discuss.tchncs.de
    link
    fedilink
    English
    arrow-up
    16
    ·
    edit-2
    9 months ago
    GET /api/database?query=SELECT+++name+++FROM+++users+++WHERE+++id=42
    

    I’ve seen that exact type of endpoint, hitting databases in production. 🔥

    • ChillPenguin@lemmy.world
      link
      fedilink
      English
      arrow-up
      6
      ·
      9 months ago

    • surewhynotlem@lemmy.world
      link
      fedilink
      English
      arrow-up
      1
      ·
      9 months ago

      If that’s a pass through, that’s bad.

      If that’s used for authentication, authorization, credential limiting, or rate limiting, then sure.

      • sebsch@discuss.tchncs.de
        link
        fedilink
        English
        arrow-up
        3
        ·
        9 months ago

        There is no context in this world validating this level of unsanitized SQL. Even for internal use this is bad, since it bypasses the auth of server and dbms.

        • surewhynotlem@lemmy.world
          link
          fedilink
          English
          arrow-up
          1
          ·
          9 months ago

          That is a very good point.

Programmer Humor@lemmy.world

programmerhumor@lemmy.world

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: [email protected]
Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 2 users / day
  • 111 users / week
  • 112 users / month
  • 940 users / 6 months
  • 1 local subscriber
  • 1.72K subscribers
  • 62 Posts
  • 128 Comments
  • Modlog
  • mods:
  • usr_bin_env@lemmy.world
  • BE: 0.19.9
  • Modlog
  • Instances
  • Docs
  • Code
  • join-lemmy.org