5CS024-Team1 / asset-tracker-web

Web app for NHS Asset Tracker project
http://mi-linux.wlv.ac.uk/~1700471/asset-tracker-web/
MIT License
3 stars 3 forks source link

Is Attribute input user input? #6

Closed Philwlv closed 4 years ago

Philwlv commented 4 years ago

https://github.com/5CS024-Team1/asset-tracker-web/blob/53b5078c487b3076a96e9ac574b3d85dd631525a/api/assets/allocate/index.php#L20 Are the attributes user input? this will need sanitizing and filtering with in the function if so. 😄

JoshLmao commented 4 years ago

Yes, they are. I'll amend issue #7 to be a general sanitizing/filtering to do so if you find any more, reference it in there

Philwlv commented 4 years ago

Awesome, I'm still getting use to this platform so I'll prob be a annoyingly amateurish for a good while 😄