|
|
|
|
|
by Klathmon
3310 days ago
|
|
or it was pulled from a GET parameter. The point is that regardless of where it came from parameterized queries are a staple of programming now, and having an example without it would be like having an example of a login system be if (username in db && password in db) { login() }
|
|
There are valid cases where you're sure that the thing you're looking at is a valid id (ie. you already pulled it out of the database or by generating it yourself), not every program is a webapp that's handling user input, and examples like this aren't meant to teach you best security practices.
And yes the login system example would be acceptable if you're discussing something entirely unrelated to actually implementing one.