ToDo: support for parameters in EXECUTE statement

Поиск
Список
Период
Сортировка
От Pavel Stehule
Тема ToDo: support for parameters in EXECUTE statement
Дата
Msg-id AANLkTimVb2yOUse0kcGz7GM69tETY7px7K7L3+swDOzP@mail.gmail.com
обсуждение исходный текст
Ответы Re: ToDo: support for parameters in EXECUTE statement
Список pgsql-hackers
Hello

The EXECUTE statement doesn't support a parametrization via
SPI_execute_with_args call and PQexecParams too. It can be a security
issue. If somebody use a prepared statement as protection to sql
injection, then all security goes out, because he has to call EXECUTE
without parametrization.

Regards

Pavel Stehule


В списке pgsql-hackers по дате отправления: