fix: sanitize NOTIFY channel name to prevent SQL injection #241
Labels
No labels
bug
documentation
enhancement
investigation
nice-to-have
performance
production-ready
testing
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
ash/eskit#241
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Problem
pgstore/notifier.gousesfmt.Sprintf("NOTIFY %s", channel)— if channel name contains SQL, it could be injected. Low risk (app-configured) but sloppy.Solution
Validate channel name is
[a-zA-Z0-9_]only. Reject or sanitize on construction.Pillar: Security