<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: queryFeatures SQL Injection in ArcGIS JavaScript Maps SDK Questions</title>
    <link>https://community.esri.com/t5/arcgis-javascript-maps-sdk-questions/queryfeatures-sql-injection/m-p/1315640#M81865</link>
    <description>&lt;P&gt;That could definitely work! Do you have a link to documentation for how to call it programmatically?&lt;/P&gt;</description>
    <pubDate>Fri, 04 Aug 2023 17:47:52 GMT</pubDate>
    <dc:creator>AddisonShaw</dc:creator>
    <dc:date>2023-08-04T17:47:52Z</dc:date>
    <item>
      <title>queryFeatures SQL Injection</title>
      <link>https://community.esri.com/t5/arcgis-javascript-maps-sdk-questions/queryfeatures-sql-injection/m-p/1313678#M81820</link>
      <description>&lt;P&gt;Looking at integrating&amp;nbsp;&lt;A href="https://developers.arcgis.com/javascript/latest/api-reference/esri-layers-FeatureLayer.html#queryFeatures" target="_self"&gt;queryFeatures&lt;/A&gt;&amp;nbsp;into our application to segment a large feature service by client.&lt;BR /&gt;&lt;BR /&gt;We have concerns about SQL Injection with this approach as it would be somewhat trivial to modify the client-side where clause to return whatever data you want from a layer.&lt;/P&gt;&lt;P&gt;How are we supposed to handle this use case? Is it possible to proxy a feature service through a backend service that itself is using something like the ArcGIS REST API? That way we could essentially hide the query implementation from end users.&lt;/P&gt;</description>
      <pubDate>Mon, 31 Jul 2023 16:28:54 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-javascript-maps-sdk-questions/queryfeatures-sql-injection/m-p/1313678#M81820</guid>
      <dc:creator>AddisonShaw</dc:creator>
      <dc:date>2023-07-31T16:28:54Z</dc:date>
    </item>
    <item>
      <title>Re: queryFeatures SQL Injection</title>
      <link>https://community.esri.com/t5/arcgis-javascript-maps-sdk-questions/queryfeatures-sql-injection/m-p/1315326#M81858</link>
      <description>&lt;P&gt;Not sure if it helps in your specific use case, but if you are using an online hosted Feature Layer I would suggest you check out the capability to create hosted &lt;A href="https://doc.arcgis.com/en/arcgis-online/manage-data/create-hosted-views.htm" target="_self"&gt;Feature Layer View&lt;/A&gt; and it's ability to configure filters.&lt;/P&gt;</description>
      <pubDate>Thu, 03 Aug 2023 21:41:41 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-javascript-maps-sdk-questions/queryfeatures-sql-injection/m-p/1315326#M81858</guid>
      <dc:creator>JohnGrayson</dc:creator>
      <dc:date>2023-08-03T21:41:41Z</dc:date>
    </item>
    <item>
      <title>Re: queryFeatures SQL Injection</title>
      <link>https://community.esri.com/t5/arcgis-javascript-maps-sdk-questions/queryfeatures-sql-injection/m-p/1315640#M81865</link>
      <description>&lt;P&gt;That could definitely work! Do you have a link to documentation for how to call it programmatically?&lt;/P&gt;</description>
      <pubDate>Fri, 04 Aug 2023 17:47:52 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-javascript-maps-sdk-questions/queryfeatures-sql-injection/m-p/1315640#M81865</guid>
      <dc:creator>AddisonShaw</dc:creator>
      <dc:date>2023-08-04T17:47:52Z</dc:date>
    </item>
  </channel>
</rss>

