Code RoomSQL injection via sort parameter
HardPrep Room Coding #1783

SQL injection via sort parameter

Code reviewDatabases & SQLSenior–Staff~24 min

Review this Go list endpoint with client-controlled sorting.

What a strong answer looks like

Separate real bugs from style. Rank issues by severity, point at the root cause rather than the symptom, and suggest a concrete fix, specific and kind.

0:00 of about 24 min
Mark a line and say what kind of problem it is.0 findings
1func ListUsers(w http.ResponseWriter, r *http.Request) {
2 sortBy := r.URL.Query().Get("sort") // e.g. "name", "created_at"
3 order := r.URL.Query().Get("order") // "asc" / "desc"
4 query := fmt.Sprintf(
5 "SELECT id, name FROM users ORDER BY %s %s", sortBy, order)
6 rows, err := db.Query(query)
7 if err != nil { http.Error(w, "error", 500); return }
8 // ... scan and return
9}
Which questions mattered is sealed until you submit. Telling you now would just be handing over the edge cases.