
PagerDuty’s Security Training for Engineers
Coding Blocks
You Can't Perameterize Everything
You can't perameterize everything. You basically never ever ever use the raw input as is to modify the query directly. If you need a case statement, find. But never ever, ever use the external input to drive thatkind stuff. And even if you do everything right right, because you're already in this, like, let's call it maybe like an anti pattern of how to u how to interact with the data base, what you're setting it up for are people who might not be as educated as you. So i kind of don't even like the idea of trying to construct sequel in your aplayery. Absolutely.
00:00
Transcript
Play full episode
Remember Everything You Learn from Podcasts
Save insights instantly, chat with episodes, and build lasting knowledge - all powered by AI.