Hacker News
new
|
past
|
comments
|
ask
|
show
|
jobs
|
submit
login
Tostino
24 days ago
|
parent
|
context
|
favorite
| on:
SQL Injection as a Feature
Hell, your user can have no write access at all, but the function or procedure can be using SECURITY DEFINER and the code inside it will run with the permissions of the function owner rather than the calling user allowing writes to happen.
Trusting a select to be read only is naive.
Guidelines
|
FAQ
|
Lists
|
API
|
Security
|
Legal
|
Apply to YC
|
Contact
Search:
Trusting a select to be read only is naive.