Field Manual PHP / Laravel reference
← Security

SQL injection

Injection happens when input changes SQL structure instead of remaining data.

What it is

Injection happens when input changes SQL structure instead of remaining data.

When to use it

Bind values and whitelist dynamic identifiers.

Syntax

// Bad:
DB::select("SELECT * FROM users WHERE id = $id");
// Good:
DB::select("SELECT * FROM users WHERE id = ?", [$id]);
// Preferred:
User::whereKey($id)->firstOrFail();

Example

$allowed = ["created_at", "id"];
$sort = $request->input("sort", "id");
abort_unless(in_array($sort, $allowed, true), 422);
$orders = $request->user()->orders()->orderBy($sort)->paginate(20);

Common mistakes

Bound parameters cannot represent column names; raw SQL must not interpolate input.

Related topics

Dependency injection