Avoiding SQL Injection Flaws with Prepared Statements

Game development with Board Game Arena Studio
Post Reply
User avatar
wdspider
Posts: 56
Joined: 19 July 2024, 05:58

Avoiding SQL Injection Flaws with Prepared Statements

Post by wdspider »

Hi,

Is there a way I can access the underlying mysqli instance within the App_DbObject class so that I can use Prepared Statements instead of manually creating the sql strings?

Thanks :)
User avatar
thoun
Posts: 1620
Joined: 10 December 2020, 22:25

Re: Avoiding SQL Injection Flaws with Prepared Statements

Post by thoun »

No you can't currently, you must use framework DB functions.
But you should check your inputs using the StringParam ( https://en.doc.boardgamearena.com/Main_ ... attributes ) so your SQL should only have values you filtered first (and most of the time you'll just use int and bool so no check necessary).
Post Reply

Return to “Developers”