Security Foundations / Exercise
Separate code from untrusted data
Compare SQL concatenation with parameter binding using controlled strings. No real target or database is contacted.
You will learn to
- Explain injection as a boundary failure
- Construct a parameterized request
- Separate validation from authorization
Before you start
Strings and simple SQL concepts
The vulnerable idea
Concatenating user input into SQL lets punctuation change the grammar. This lab represents a query as text and bound values. It never connects to a database, scans a target or executes SQL. The hostile-looking name is a fixed classroom fixture.
Build a boundary
Return text equal to SELECT id FROM students WHERE name = $1 and values containing the exact supplied name. Do not manually quote the name. In a real application use the database driver’s parameter API; this model illustrates that contract.
Authorization is separate
Binding prevents data from becoming SQL syntax. It does not decide whether the caller may see the row. Ownership checks and database permissions remain necessary. Explain both boundaries before completing the exercise.
Try it yourself
function lookup(name) {
return {text: 'SELECT id FROM students WHERE name = ' + name, values: []};
}
console.log(lookup("O'Reilly"));Enable JavaScript for this interactive activity. You can read all lesson explanations above without it.