<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Potential for SQL injection using QueryDataSource in ArcGIS JavaScript Maps SDK Questions</title>
    <link>https://community.esri.com/t5/arcgis-javascript-maps-sdk-questions/potential-for-sql-injection-using-querydatasource/m-p/22520#M1956</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I think this is hitting a REST Endpoint so the security is handled by ArcServer. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 04 Feb 2015 19:54:53 GMT</pubDate>
    <dc:creator>PaulCrickard</dc:creator>
    <dc:date>2015-02-04T19:54:53Z</dc:date>
    <item>
      <title>Potential for SQL injection using QueryDataSource</title>
      <link>https://community.esri.com/t5/arcgis-javascript-maps-sdk-questions/potential-for-sql-injection-using-querydatasource/m-p/22519#M1955</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I would really like to start adding layers to my applications using Dynamic Layers and the &lt;A href="https://developers.arcgis.com/javascript/jsapi/querydatasource-amd.html"&gt;QueryDataSource &lt;/A&gt;class.&amp;nbsp; This would allow me to display some relatively complex relationships on the fly with minimal input from users and without having to pre-symbolize and anticipate all possible combinations in a map service beforehand. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My only concern is that exposing SQL queries through a client-side application might open us up to SQL injection.&amp;nbsp; Is anyone out there working with the QueryDataSource class?&amp;nbsp; Are there any built-in safegaurds against SQL injection?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 04 Feb 2015 15:21:35 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-javascript-maps-sdk-questions/potential-for-sql-injection-using-querydatasource/m-p/22519#M1955</guid>
      <dc:creator>BillDaigle</dc:creator>
      <dc:date>2015-02-04T15:21:35Z</dc:date>
    </item>
    <item>
      <title>Re: Potential for SQL injection using QueryDataSource</title>
      <link>https://community.esri.com/t5/arcgis-javascript-maps-sdk-questions/potential-for-sql-injection-using-querydatasource/m-p/22520#M1956</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I think this is hitting a REST Endpoint so the security is handled by ArcServer. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 04 Feb 2015 19:54:53 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-javascript-maps-sdk-questions/potential-for-sql-injection-using-querydatasource/m-p/22520#M1956</guid>
      <dc:creator>PaulCrickard</dc:creator>
      <dc:date>2015-02-04T19:54:53Z</dc:date>
    </item>
    <item>
      <title>Re: Potential for SQL injection using QueryDataSource</title>
      <link>https://community.esri.com/t5/arcgis-javascript-maps-sdk-questions/potential-for-sql-injection-using-querydatasource/m-p/22521#M1957</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It looks like the parameter "&lt;SPAN class="usertext"&gt;useStandardizedQueries" that was added at 10.2&amp;nbsp; &lt;A href="http://resources.arcgis.com/en/help/arcgis-rest-api/index.html#//02r3000000p1000000"&gt;http://resources.arcgis.com/en/help/arcgis-rest-api/index.html#//02r3000000p1000000 &lt;/A&gt;​likely addresses my concern.&amp;nbsp; &lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 02 Jun 2015 17:07:54 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-javascript-maps-sdk-questions/potential-for-sql-injection-using-querydatasource/m-p/22521#M1957</guid>
      <dc:creator>BillDaigle</dc:creator>
      <dc:date>2015-06-02T17:07:54Z</dc:date>
    </item>
  </channel>
</rss>

