I was just wondering why the BySql QueryParam doesn't require the
IHaveValidatedThisSql case class. Looking at the source it seems that it
could be just as vulnerable to some shenanigans, although admittedly I'm not
an expert on SQL injection attacks.

Derek

--~--~---------~--~----~------------~-------~--~----~
You received this message because you are subscribed to the Google Groups 
"Lift" group.
To post to this group, send email to [email protected]
To unsubscribe from this group, send email to [EMAIL PROTECTED]
For more options, visit this group at 
http://groups.google.com/group/liftweb?hl=en
-~----------~----~----~----~------~----~------~--~---

Reply via email to