diff --git a/test_security_fix.py b/test_security_fix.py index 5195286..3e83f54 100644 --- a/test_security_fix.py +++ b/test_security_fix.py @@ -1,6 +1 @@ -# Test file for security fix demonstration -def get_user_data(user_id): - # Vulnerable: SQL injection - query = f"SELECT * FROM users WHERE id = '{user_id}'" - return db.execute(query) - + return db.execute(text("SELECT * FROM users WHERE id = :user_id"), {"user_id": user_id}) \ No newline at end of file