|
|
|
|
|
by danneu
4076 days ago
|
|
Your driver should be able to handle parameterized queries for you. query('SELECT * FROM users WHERE id = ANY ($1::int[])', [1, 2, 3]);
query('SELECT * FROM users WHERE lower(uname) = lower($1)', 'foo');
Where's the injection vulnerability? |
|