Security Foundations / Exercise

Separate code from untrusted data

Compare SQL concatenation with parameter binding using controlled strings. No real target or database is contacted.

You will learn to

  • Explain injection as a boundary failure
  • Construct a parameterized request
  • Separate validation from authorization

Before you start

Strings and simple SQL concepts

The vulnerable idea

Concatenating user input into SQL lets punctuation change the grammar. This lab represents a query as text and bound values. It never connects to a database, scans a target or executes SQL. The hostile-looking name is a fixed classroom fixture.

Build a boundary

Return text equal to SELECT id FROM students WHERE name = $1 and values containing the exact supplied name. Do not manually quote the name. In a real application use the database driver’s parameter API; this model illustrates that contract.

Authorization is separate

Binding prevents data from becoming SQL syntax. It does not decide whether the caller may see the row. Ownership checks and database permissions remain necessary. Explain both boundaries before completing the exercise.

Try it yourself

function lookup(name) {
  return {text: 'SELECT id FROM students WHERE name = ' + name, values: []};
}
console.log(lookup("O'Reilly"));

Enable JavaScript for this interactive activity. You can read all lesson explanations above without it.

Continue exploring