Parameterized querying and SQL injection with ActiveRecord https://gist.github.com/JoshCheek/54fd1bd9c045829c5a70a51c0398181d …
-
-
Replying to @josh_cheek
Keep in mind that https://gist.github.com/JoshCheek/54fd1bd9c045829c5a70a51c0398181d#file-sql_injection_and_parameterizing_queries-rb-L22-L26 … can get you into trouble if using MySQL
1 reply 0 retweets 0 likes -
Replying to @josh_cheek
Hash form we know the type of the column and can protect you. String form we'll determine quoting based on argument type
7:51 AM - 14 Jul 2017
from Albuquerque, NM
0 replies
0 retweets
0 likes
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.