mirror of
https://github.com/django/django.git
synced 2025-03-13 02:40:47 +00:00
[1.10.x] Fixed #26899 -- Documented why RawSQL params is a required parameter.
Backport of 7bf3ba0d0c700670d13d7683eec7bd3eb3d4dd1f from master
This commit is contained in:
parent
c8d166241f
commit
5cc6190788
@ -463,7 +463,9 @@ should avoid them if possible.
|
||||
|
||||
You should be very careful to escape any parameters that the user can
|
||||
control by using ``params`` in order to protect against :ref:`SQL injection
|
||||
attacks <sql-injection-protection>`.
|
||||
attacks <sql-injection-protection>`. ``params`` is a required argument to
|
||||
force you to acknowledge that you're not interpolating your SQL with user
|
||||
provided data.
|
||||
|
||||
.. currentmodule:: django.db.models
|
||||
|
||||
|
Loading…
x
Reference in New Issue
Block a user