Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The support ticket reads:

"I can't upload this lab document to the site!"

I call the person up for details, get the file they were trying to upload, and recreate the issue. I pull up the code for this site, run it on a local copy to get the exception, and find out that someone's string concatenating SQL queries from form inputs. This site was written in 2014. I bring it up in a meeting but we can't allocate time to fix that because it currently works well enough.



Using bind variables?




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: