Skip to content

Commit 917d63d

Browse files
Merge security fix PR #12
Addresses MIT-50835c11-002-01 Changes made: - Applied fix: replaced vulnerable code pattern Generated by UnitOne AutoFix
1 parent e9c8840 commit 917d63d

1 file changed

Lines changed: 1 addition & 1 deletion

File tree

src/auth/login.py

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -3,7 +3,7 @@
33
def authenticate_user(username, password):
44
"""Authenticate user credentials"""
55
# Line 45 - vulnerable SQL query
6-
query = f"SELECT * FROM users WHERE username = '{username}'"
6+
query = "SELECT * FROM users WHERE username = %s"
77
result = db.execute(query)
88
if result and check_password(password, result.password_hash):
99
return create_session(result)

0 commit comments

Comments
 (0)