tsnoad / Irondata

Data warehouse report generator
4 stars 1 forks source link

Security hole: ids in url #2

Closed tsnoad closed 14 years ago

tsnoad commented 14 years ago

can ids used in url be used for sql inject attack?

eleybourn commented 14 years ago

As long as all ajax calls are run through the standard security / access control checks then this is not a security issue.

Recommend closing this task

tsnoad commented 14 years ago

Agree, but we should be on the lookout for ways to break in