1
0
mirror of https://github.com/danog/psalm.git synced 2024-12-05 13:10:49 +01:00
psalm/docs/running_psalm/issues/TaintedSql.md

19 lines
377 B
Markdown
Raw Normal View History

# TaintedSql
Emitted when user-controlled input can be passed into to a SQL command.
```php
<?php
class A {
public function deleteUser(PDO $pdo) : void {
$userId = self::getUserId();
$pdo->exec("delete from users where user_id = " . $userId);
}
public static function getUserId() : string {
return (string) $_GET["user_id"];
}
}
```