• surewhynotlem@lemmy.world
    link
    fedilink
    English
    arrow-up
    1
    ·
    3 days ago

    If that’s a pass through, that’s bad.

    If that’s used for authentication, authorization, credential limiting, or rate limiting, then sure.

    • sebsch
      link
      fedilink
      English
      arrow-up
      3
      ·
      3 days ago

      There is no context in this world validating this level of unsanitized SQL. Even for internal use this is bad, since it bypasses the auth of server and dbms.