Hi Patrick

SQL Injection is not an issue with Sphinx - at least not with the Sphinx API 
(which is what Thinking Sphinx currently uses for queries).

Cheers

-- 
Pat

On 21/06/2011, at 2:33 AM, patrick99e99 wrote:

> Hi,
> 
> I am working on a project that has some code that calls .facets with
> params[:order] directly in it..  I was wondering if this is at risk
> for sql injection, or if sphinx works differently than ActiveRecord
> and this is not a concern.  ?
> 
> Thanks.
> 
> -patrick
> 
> -- 
> You received this message because you are subscribed to the Google Groups 
> "Thinking Sphinx" group.
> To post to this group, send email to [email protected].
> To unsubscribe from this group, send email to 
> [email protected].
> For more options, visit this group at 
> http://groups.google.com/group/thinking-sphinx?hl=en.
> 

-- 
You received this message because you are subscribed to the Google Groups 
"Thinking Sphinx" group.
To post to this group, send email to [email protected].
To unsubscribe from this group, send email to 
[email protected].
For more options, visit this group at 
http://groups.google.com/group/thinking-sphinx?hl=en.

Reply via email to