sul-dlss / sul-requests

Rails application for requesting materials from Stanford University Library
Other
4 stars 0 forks source link

Validate hrids. #2547

Closed cbeer closed 3 months ago

cbeer commented 3 months ago

Although we're no longer allowing graphql injection, apparently FOLIO/okapi allows some kind of sql injection.

Deployed pending https://github.com/sul-dlss/folio-graphql/pull/213.