Re: Protection from SQL injection - Mailing list pgsql-hackers

From Andrew Dunstan
Subject Re: Protection from SQL injection
Date
Msg-id 4819F952.1020102@dunslane.net
Whole thread Raw
In response to Re: Protection from SQL injection  ("Thomas Mueller" <thomas.tom.mueller@gmail.com>)
List pgsql-hackers

Thomas Mueller wrote:
> Disabling literals is still the only way to actually protect from SQL
> injection. Except Meredith's libdejector, which is even a bit better
> as far as I see, but requires more work from the developer. I don't
> count Microsoft LINQ (or Java Quaere) currently because that would
> require a complete re-write of the application.
>
>
>   

I honestly don't think there's any chance of this happening, for the 
many good reasons previously covered in this debate.

cheers

andrew


pgsql-hackers by date:

Previous
From: KaiGai Kohei
Date:
Subject: Re: [0/4] Proposal of SE-PostgreSQL patches
Next
From: Tom Lane
Date:
Subject: Re: Protection from SQL injection