microsoft / microsoft/go-sqlcmd
Refactor the queries executed wth user input
Open
Nobody has claimed this yet.
enhancement
Security
- Dominant language
- Go
- Stars
- 595
- Forks
- 91
- Avg merge
- 9h 35m
- Merged PRs (30d)
- 1
Description
Queries that have user input should be executed with parametrized queries and should possibly use sp_executesql
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
No files, tests, or entry points are named. Start by locating the query execution paths that accept user input and review how parameterized queries and sp_executesql apply there. Done means the affected queries no longer interpolate user input and relevant tests verify their execution.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- go, sql
- Domain
- cli, databases, security
- Issue type
- Refactor
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 32/100