[postmodern-devel] sql injection

Marijn Haverbeke marijnh at gmail.com
Fri Jun 25 08:55:44 UTC 2010


Hi Phil,

> How susceptible is dao objects to sql injection and what measures would
> be suggested to prevent sql injection if it is possible with dao objects.

Unless I made a major blunder somewhere, proper use of s-sql and dao
objects are completely safe from sql injection. (Improper use would be
inserting an unescaped string using the :raw operator.)

Best,
Marijn




More information about the postmodern-devel mailing list