SQL injection via sort parameter
Review this Go list endpoint with client-controlled sorting.
What a strong answer looks like
Separate real bugs from style. Rank issues by severity, point at the root cause rather than the symptom, and suggest a concrete fix, specific and kind.
0:00 of about 24 min
Mark a line and say what kind of problem it is.0 findings
1func ListUsers(w http.ResponseWriter, r *http.Request) {
2 sortBy := r.URL.Query().Get("sort") // e.g. "name", "created_at"
3 order := r.URL.Query().Get("order") // "asc" / "desc"
4 query := fmt.Sprintf(
5 "SELECT id, name FROM users ORDER BY %s %s", sortBy, order)
6 rows, err := db.Query(query)
7 if err != nil { http.Error(w, "error", 500); return }
8 // ... scan and return
9}
Which questions mattered is sealed until you submit. Telling you now would just be handing over the edge cases.
Run or narrate your approach, then ask the coach.