From 221a3f274800bd42e7820c0ebfe73c345ae679d8 Mon Sep 17 00:00:00 2001 From: monoid Date: Sat, 2 Jan 2021 15:39:18 +0900 Subject: [PATCH] add comment about sql injection --- src/db/contents.ts | 1 + 1 file changed, 1 insertion(+) diff --git a/src/db/contents.ts b/src/db/contents.ts index 3cdb65e..485fd5b 100644 --- a/src/db/contents.ts +++ b/src/db/contents.ts @@ -75,6 +75,7 @@ class KnexContentsAccessor implements ContentAccessor{ query = query.from("contents"); } if(word !== undefined){ + //don't worry about sql injection. query = query.where('title','like',`%${word}%`); } if(content_type !== undefined){