7
如何使程序员停止编写易受SQL注入攻击的代码?
有时您会很忙,将一些小任务委派给初级程序员。但是,如果您没有给予足够的关注,您就会在生产中使用这种代码: class DivtoggleController extends Zend_Controller_Action { public function closeAction() { /* ... code removed for brevity ... */ $req = $this->getRequest(); $formData = $req->getPost(); $d = $formData['div']; $i = $formData['id']; $dm = new Model_DivtoggleManager(); $rs = $dm->setDivToggleById($d, $i); } } class Model_DivtoggleManager extends Zend_Db_Table { public function setDivToggleById($div, $id) { …