annotate tests/disallowed.ur @ 2245:27899da8780b

Sqlcache allows any expression injected into SQL.
author Ziv Scully <ziv@mit.edu>
date Sun, 02 Aug 2015 18:25:42 -0700
parents 001638622c4f
children
rev   line source
adam@1521 1 cookie bad : url
adam@1521 2
adam@1521 3 fun worse (x : url) : transaction page = return <xml/>