You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Developer manual: allowlist user-supplied columns and sort orders in database.rst #15682
developer_manual/basics/storage/database.rst explains named parameters well, but not the case where they don't help: column names and sort directions can't be parameters.
Add a short note: if a column name or sort order comes from the user, check it against an allowlist before passing it to orderBy() / select().
Add a small example (e.g. a match on the allowed values).
developer_manual/basics/storage/database.rstexplains named parameters well, but not the case where they don't help: column names and sort directions can't be parameters.orderBy()/select().matchon the allowed values).