Rename executeRaw → executeRawUnsafe to make SQL injection risk explicit
Local Build and Deploy / deploy (push) Successful in 1m1s
Local Build and Deploy / deploy (push) Successful in 1m1s
The method wraps Prisma's which trusts the caller to use ? placeholders. The Unsafe suffix is a naming convention that signals 'review caller for parameterization'.
This commit is contained in:
1 parent
e5ae51bff7
commit
bef458dbf8
1 file changed
+6
-1
@@ -105,7 +105,12 @@ export class DbService {
|
||||
}
|
||||
}
|
||||
|
||||
async executeRaw(query: string, ...values: unknown[]): Promise<number> {
|
||||
/**
|
||||
* Execute a raw SQL string with parameterized ? placeholders.
|
||||
* Named "Unsafe" because the caller is responsible for using ? placeholders
|
||||
* and never interpolating user input directly into the query string.
|
||||
*/
|
||||
async executeRawUnsafe(query: string, ...values: unknown[]): Promise<number> {
|
||||
try {
|
||||
return await this.client.$executeRawUnsafe(query, ...values);
|
||||
} catch (cause) {
|
||||
|
||||
Reference in new issue
Block a user