Skip to content

Document how to avoid SQL injection with Dapper on bobby-tables.com #1517

Open
@zspitz

Description

@zspitz

bobby-tables.com, a website devoted to avoiding SQL injection on various platforms, has a page on Dapper.

The page only has some minimal examples. Perhaps it might be a good idea for someone more familiar with the Dapper API to expand the text and examples?

At minimum, I think there ought to be a comprehensive list of Dapper methods which take raw SQL, and are thus potentially vulnerable to SQL injection if parameters aren't used.

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions