Rename executeRaw → executeRawUnsafe to make SQL injection risk explicit
Local Build and Deploy / deploy (push) Successful in 1m1s
Local Build and Deploy / deploy (push) Successful in 1m1s
The method wraps Prisma's which trusts the caller to use ? placeholders. The Unsafe suffix is a naming convention that signals 'review caller for parameterization'.
This commit is contained in:
1 parent
e5ae51bff7
commit
bef458dbf8
1 file changed
+6
-1
@@ -105,7 +105,12 @@ export class DbService {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
async executeRaw(query: string, ...values: unknown[]): Promise<number> {
|
/**
|
||||||
|
* Execute a raw SQL string with parameterized ? placeholders.
|
||||||
|
* Named "Unsafe" because the caller is responsible for using ? placeholders
|
||||||
|
* and never interpolating user input directly into the query string.
|
||||||
|
*/
|
||||||
|
async executeRawUnsafe(query: string, ...values: unknown[]): Promise<number> {
|
||||||
try {
|
try {
|
||||||
return await this.client.$executeRawUnsafe(query, ...values);
|
return await this.client.$executeRawUnsafe(query, ...values);
|
||||||
} catch (cause) {
|
} catch (cause) {
|
||||||
|
|||||||
Reference in new issue
Block a user