Coding Blocks cover image

PagerDuty’s Security Training for Engineers

Coding Blocks

00:00

You Can't Perameterize Everything

You can't perameterize everything. You basically never ever ever use the raw input as is to modify the query directly. If you need a case statement, find. But never ever, ever use the external input to drive thatkind stuff. And even if you do everything right right, because you're already in this, like, let's call it maybe like an anti pattern of how to u how to interact with the data base, what you're setting it up for are people who might not be as educated as you. So i kind of don't even like the idea of trying to construct sequel in your aplayery. Absolutely.

Transcript
Play full episode

The AI-powered Podcast Player

Save insights by tapping your headphones, chat with episodes, discover the best highlights - and more!
App store bannerPlay store banner
Get the app