SQL injection
Injection happens when input changes SQL structure instead of remaining data.
What it is
Injection happens when input changes SQL structure instead of remaining data.
When to use it
Bind values and whitelist dynamic identifiers.
Syntax
// Bad:
DB::select("SELECT * FROM users WHERE id = $id");
// Good:
DB::select("SELECT * FROM users WHERE id = ?", [$id]);
// Preferred:
User::whereKey($id)->firstOrFail();Example
$allowed = ["created_at", "id"];
$sort = $request->input("sort", "id");
abort_unless(in_array($sort, $allowed, true), 422);
$orders = $request->user()->orders()->orderBy($sort)->paginate(20);Common mistakes
Bound parameters cannot represent column names; raw SQL must not interpolate input.