|
Posted by Rik on 02/06/07 07:10
Toby A Inkster <usenet200701@tobyinkster.co.uk> wrote:
> Jerry Stuckle wrote:
>
>> Don't be dense, Tony. This is obviously some debug code. In the real
>> code he would be opening the connection and executing the sql.
>
> That's your assumption.
>
> My assumption is that in the real code, *if* he opened a connection to
> the
> database, then he'd be sure to authenticate the user first, by at least
> username/password and preferably IP address too.
>
> Besides which, there are perfectly good reasons you might want to pass a
> SQL query to a script that does not execute it.
Sure there are. And all of them are better served with a POST.
--
Rik Wasmus
Navigation:
[Reply to this message]
|