× Heads up!

Aqua Data Studio / nhilam

Follow
IDE for Relational Databases
×
bobfromtn reported 2017-07-03T17:57:53Z  · tariqrahiman last modified 2017-07-06T17:51:58Z

Aquascript parameterized SQL query to mitigate SQL injection attack concerns


customer request
Priority Major
Complexity Unknown
Component Open API - RDBMS
Version 18.0

I've been looking (so far without success) for a way to build a SQL Statement using parameters in Aquascript.  This would avoid string concatenation in Aquascript to build the SQL and instead have a prepared statement with parameters.  The motive would be to mitigate the risk of a SQL Injection attack when you cannot be confident of the input text safety.  Is that an available capability?  If so, how do you execute a query with this kind of SQL statement?

Issue #15367

Closed
Fixed
Resolved 2017-07-04T23:44:48Z
 
 
Completion
No due date
No fixed build
No time estimate

About AquaClusters Privacy Policy Support Version - 19.0.2-4 AquaFold, Inc Copyright © 2007-2017