Table name not parameterized
Review this Java DAO method.
What a strong answer looks like
Separate real bugs from style. Rank issues by severity, point at the root cause rather than the symptom, and suggest a concrete fix, specific and kind.
0:00 of about 30 min
Mark a line and say what kind of problem it is.0 findings
1public List<Report> reportsForTenant(String tenantId) throws SQLException {
2 String table = "reports_" + tenantId; // per-tenant sharded table
3 String sql = "SELECT id, title, body FROM " + table
4 + " WHERE archived = false ORDER BY id DESC LIMIT 100";
5 try (Statement st = conn.createStatement();
6 ResultSet rs = st.executeQuery(sql)) {
7 List<Report> out = new ArrayList<>();
8 while (rs.next()) {
9 out.add(new Report(rs.getLong("id"), rs.getString("title"), rs.getString("body")));
10 }
11 return out;
12 }
13}
Which questions mattered is sealed until you submit. Telling you now would just be handing over the edge cases.
Run or narrate your approach, then ask the coach.