Re: svn commit: r1091262 - /subversion/trunk/subversion/libsvn_wc/wc_db.c
From: Hyrum K Wright <hyrum_at_hyrumwright.org>
Date: Mon, 11 Apr 2011 21:58:48 -0500
On Mon, Apr 11, 2011 at 9:41 PM, Greg Stein <gstein_at_gmail.com> wrote:
$ svnd blame subversion/libsvn_subr/sqlite.c | grep svn_sqlite__prepare
It looks like you introduced (or resurrected it) in r873188.
> I'm basically -1 on that.
This is still a prepared statement, arguments are still bound using
Plus, we're talking about local data here. While sql injection is a
On a higher-level, if we *don't* use this API, what are your
-Hyrum
|
This is an archived mail posted to the Subversion Dev mailing list.
This site is subject to the Apache Privacy Policy and the Apache Public Forum Archive Policy.