cocoon-dev mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From Andrew Savory <>
Subject Re: R: R: A case of SQL injection
Date Wed, 06 Nov 2002 09:44:39 GMT

On Tue, 5 Nov 2002, Ilya A. Kriveshko wrote:

> With my limited knowledge of this subject (BTW, I'm not insecure -
> I'm polite) I don't see data checking as the job of the DBMS. DBMS
> simply maintains the data, executes queries that the client provides,
> returns the results and ensures that proper side-effects occur.

Hi Ilya,

We're probably straying off-topic here, but I thought I'd just say a word
or two about why you might want data checking at the DBMS level.

The benefit of letting the DBMS decide what is and isn't good data is that
you can then change the application on the front of the database easily
(or write a new one), knowing that the rules for what data can be used and
how it can be accessed are maintained at the database level (and don't
need to be ported from application to application).

Although I'm all for checking at the application level too -- you can
never be over careful!


Andrew Savory                                Email:
Managing Director                              Tel:  +44 (0)870 741 6658
Luminas Internet Applications                  Fax:  +44 (0)700 598 1135
This is not an official statement or order.    Web:

To unsubscribe, e-mail:
For additional commands, email:

View raw message