Search Postgresql Archives

How does one make the following psql statement sql-injection resilient?

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



psql "$SERVICE" \
     --echo-queries \
     --set=string_input="${1:-ok_to_return}" \
     --set=start="${2:-5}" \
     --set=end="${3:-10}" \
<<'SQL'
    SELECT idx
        FROM generate_series(1, 20) gs (idx)
        WHERE 'short-circuit' != :'string_input'
        AND idx BETWEEN :start AND :end;
SQL

# (6 rows)

--set=end="${3:-10 AND false}"

# (0 rows)

Am I forced to represent the input as text (using :'end') and then perform a conversion to integer?

Thanks!

David J.


[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[Index of Archives]     [Postgresql Jobs]     [Postgresql Admin]     [Postgresql Performance]     [Linux Clusters]     [PHP Home]     [PHP on Windows]     [Kernel Newbies]     [PHP Classes]     [PHP Books]     [PHP Databases]     [Postgresql & PHP]     [Yosemite]
  Powered by Linux