Coding Blocks cover image

PagerDuty’s Security Training for Engineers

Coding Blocks

CHAPTER

You Can't Perameterize Everything

You can't perameterize everything. You basically never ever ever use the raw input as is to modify the query directly. If you need a case statement, find. But never ever, ever use the external input to drive thatkind stuff. And even if you do everything right right, because you're already in this, like, let's call it maybe like an anti pattern of how to u how to interact with the data base, what you're setting it up for are people who might not be as educated as you. So i kind of don't even like the idea of trying to construct sequel in your aplayery. Absolutely.

00:00
Transcript
Play full episode

Remember Everything You Learn from Podcasts

Save insights instantly, chat with episodes, and build lasting knowledge - all powered by AI.
App store bannerPlay store banner