1
0
mirror of https://github.com/django/django.git synced 2025-03-13 10:50:55 +00:00

[1.10.x] Fixed #26899 -- Documented why RawSQL params is a required parameter.

Backport of 7bf3ba0d0c700670d13d7683eec7bd3eb3d4dd1f from master
This commit is contained in:
petedmarsh 2016-07-21 15:28:31 +01:00 committed by Tim Graham
parent c8d166241f
commit 5cc6190788

View File

@ -463,7 +463,9 @@ should avoid them if possible.
You should be very careful to escape any parameters that the user can You should be very careful to escape any parameters that the user can
control by using ``params`` in order to protect against :ref:`SQL injection control by using ``params`` in order to protect against :ref:`SQL injection
attacks <sql-injection-protection>`. attacks <sql-injection-protection>`. ``params`` is a required argument to
force you to acknowledge that you're not interpolating your SQL with user
provided data.
.. currentmodule:: django.db.models .. currentmodule:: django.db.models