Rename executeRaw → executeRawUnsafe to make SQL injection risk explicit
Local Build and Deploy / deploy (push) Successful in 1m1s

The method wraps Prisma's  which trusts the caller
to use ? placeholders. The Unsafe suffix is a naming convention
that signals 'review caller for parameterization'.
This commit is contained in:
openhands committed 2026-07-13 12:41:11 +02:00
1 parent e5ae51bff7
commit bef458dbf8
1 file changed
+6 -1
+6 -1
View File
@@ -105,7 +105,12 @@ export class DbService {
}
}
async executeRaw(query: string, ...values: unknown[]): Promise<number> {
/**
* Execute a raw SQL string with parameterized ? placeholders.
* Named "Unsafe" because the caller is responsible for using ? placeholders
* and never interpolating user input directly into the query string.
*/
async executeRawUnsafe(query: string, ...values: unknown[]): Promise<number> {
try {
return await this.client.$executeRawUnsafe(query, ...values);
} catch (cause) {