Lemmy
  • Communities
  • Create Post
  • Create Community
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
youTellMe@lemmy.world to Programmer Humor@lemmy.worldEnglish · 1 year ago

Everyday we stray further from industry standards

lemmy.world

message-square
24
fedilink
190

Everyday we stray further from industry standards

lemmy.world

youTellMe@lemmy.world to Programmer Humor@lemmy.worldEnglish · 1 year ago
message-square
24
fedilink
  • sebsch@discuss.tchncs.de
    link
    fedilink
    English
    arrow-up
    16
    ·
    edit-2
    1 year ago
    GET /api/database?query=SELECT+++name+++FROM+++users+++WHERE+++id=42
    

    I’ve seen that exact type of endpoint, hitting databases in production. 🔥

    • ChillPenguin@lemmy.world
      link
      fedilink
      English
      arrow-up
      6
      ·
      1 year ago

    • surewhynotlem@lemmy.world
      link
      fedilink
      English
      arrow-up
      1
      ·
      1 year ago

      If that’s a pass through, that’s bad.

      If that’s used for authentication, authorization, credential limiting, or rate limiting, then sure.

      • sebsch@discuss.tchncs.de
        link
        fedilink
        English
        arrow-up
        3
        ·
        1 year ago

        There is no context in this world validating this level of unsanitized SQL. Even for internal use this is bad, since it bypasses the auth of server and dbms.

        • surewhynotlem@lemmy.world
          link
          fedilink
          English
          arrow-up
          1
          ·
          1 year ago

          That is a very good point.

Programmer Humor@lemmy.world

programmerhumor@lemmy.world

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: [email protected]
Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 1 user / day
  • 1 user / week
  • 104 users / month
  • 540 users / 6 months
  • 1 local subscriber
  • 1.78K subscribers
  • 69 Posts
  • 139 Comments
  • Modlog
  • mods:
  • usr_bin_env@lemmy.world
  • BE: 0.19.9
  • Modlog
  • Instances
  • Docs
  • Code
  • join-lemmy.org