Discussions
Categories
Groups
Community Home
Categories
INTERNAL ENABLEMENT
POPULAR
PUBLIC CLOUD
PRIVATE CLOUD
Quick Links
MY LINKS
HELPFUL TIPS
Back to website
Home
Intelligence (Analytics)
prevent sql injection in dataset
shazia
Hi,
Used some days on this problem. searched the web without finding any clear answer. i have a question regarding preventing sql injection when running birt reports.
I build the queryText in 'beforeOpen'-event.
this is an example from my beforeOpen:
this.queryText="select * from MyTable where MyTable.Age=" + reportContext.getParameterValue('ageparam') + " and MyTable.EmployeeName = '" + reportContext.getParameterValue('name_param') + "'";
But i guess this leaves the sql open for sql injection. In Java, one can use prepared statements and by that prevent sql injection. But how to achieve this in Birt when using script in beforeopen?
Solutions ?
- replace all "evil"-characters (as ' and --) before adding paramter-values to the queryText ? not fool-proof i guess?
- is it possible to run preparedstatement with java from the before-open event on dataset ?
- is it possible to run something equal to java-preparedsatement with javascript from the before open event on dataset ?
- some other solution ?
Find more posts tagged with
Comments
Hans_vd
Take a look at the report that comes with this devshare post:
http://www.birt-exchange.org/org/devshare/designing-birt-reports/832-dynamic-binding-of-in-list-parameters/
And apparently there also is a plugin available that takes care of this:
http://birtworld.blogspot.nl/2009/03/birt-multi-select-statements.html