[postmodern-devel] sql injection
    Marijn Haverbeke 
    marijnh at gmail.com
       
    Fri Jun 25 08:55:44 UTC 2010
    
    
  
Hi Phil,
> How susceptible is dao objects to sql injection and what measures would
> be suggested to prevent sql injection if it is possible with dao objects.
Unless I made a major blunder somewhere, proper use of s-sql and dao
objects are completely safe from sql injection. (Improper use would be
inserting an unescaped string using the :raw operator.)
Best,
Marijn
    
    
More information about the postmodern-devel
mailing list