DEV Community

Discussion on: Project: Basic Authentication System

Collapse
 
sqlrob profile image
Robert Myers

You should use parameters on the queries, not generate the query text. You're vulnerable to SQL injection in the user service.

Collapse
 
ulzahk profile image
Ulzahk

Thanks Robert, I will keep this in mind for future updates.