summaryrefslogtreecommitdiff
path: root/docs/ref/models
diff options
context:
space:
mode:
Diffstat (limited to 'docs/ref/models')
-rw-r--r--docs/ref/models/expressions.txt18
-rw-r--r--docs/ref/models/querysets.txt11
2 files changed, 22 insertions, 7 deletions
diff --git a/docs/ref/models/expressions.txt b/docs/ref/models/expressions.txt
index f9dec50a5d..88981198c2 100644
--- a/docs/ref/models/expressions.txt
+++ b/docs/ref/models/expressions.txt
@@ -660,11 +660,19 @@ should avoid them if possible.
.. warning::
- You should be very careful to escape any parameters that the user can
- control by using ``params`` in order to protect against :ref:`SQL injection
- attacks <sql-injection-protection>`. ``params`` is a required argument to
- force you to acknowledge that you're not interpolating your SQL with user
- provided data.
+ To protect against `SQL injection attacks
+ <https://en.wikipedia.org/wiki/SQL_injection>`_, you must escape any
+ parameters that the user can control by using ``params``. ``params`` is a
+ required argument to force you to acknowledge that you're not interpolating
+ your SQL with user-provided data.
+
+ You also must not quote placeholders in the SQL string. This example is
+ vulnerable to SQL injection because of the quotes around ``%s``::
+
+ RawSQL("select col from sometable where othercol = '%s'") # unsafe!
+
+ You can read more about how Django's :ref:`SQL injection protection
+ <sql-injection-protection>` works.
Window functions
----------------
diff --git a/docs/ref/models/querysets.txt b/docs/ref/models/querysets.txt
index d6845cffd9..a5375ea371 100644
--- a/docs/ref/models/querysets.txt
+++ b/docs/ref/models/querysets.txt
@@ -1284,8 +1284,15 @@ generated by a ``QuerySet``.
You should be very careful whenever you use ``extra()``. Every time you use
it, you should escape any parameters that the user can control by using
- ``params`` in order to protect against SQL injection attacks . Please
- read more about :ref:`SQL injection protection <sql-injection-protection>`.
+ ``params`` in order to protect against SQL injection attacks.
+
+ You also must not quote placeholders in the SQL string. This example is
+ vulnerable to SQL injection because of the quotes around ``%s``::
+
+ "select col from sometable where othercol = '%s'" # unsafe!
+
+ You can read more about how Django's :ref:`SQL injection protection
+ <sql-injection-protection>` works.
By definition, these extra lookups may not be portable to different database
engines (because you're explicitly writing SQL code) and violate the DRY