prevent-sql-injection
Handles SQL injection on Azure SQL Database beyond parameterisation: a typed sp_executesql parameter matches nothing where the same input concatenated into EXEC() returns every row; QUOTENAME returns NULL above 128 characters, so the batch built from it becomes NULL and does nothing; a dynamic ORDER BY built from one CASE over mixed types fails only for the sort key on the lower-precedence branch; dynamic SQL breaks the ownership chain, so EXECUTE AS decides what it may touch; and Always Encrypted refuses a literal (Msg 206). Use for a general injection question or a pre-production review, when a QUOTENAME-built statement returns and raises nothing, when a sort-by-column feature throws an operand type clash for one column only, when a procedure works until its query becomes dynamic, or when an encrypted column will not take a literal. Row level tenant isolation is rls-multi-tenant.
Pinned to revision eeb1c6867c2d, so it is the text this page describes rather than whatever the author pushed since.
Files
- skills/prevent-sql-injection/SKILL.md
- skills/prevent-sql-injection/references/quotename-null-and-order-by-clashes.md
Every link opens the file at its source, pinned to the revision this page describes.