Wednesday, May 14, 2008

mix Oracle: Error popup

I found an Error popup on Mix Oracle.

7 comments:

Jake said...

Hi Surachart. Would you mind using the Send Feedback link on Mix to tell me more about the error, at least what were you doing when it happened?
Thanks.

SydOracle said...

Looks like someone isn't using bind variables. Tut, Tut.

Surachart Opun said...

It was a error, when I clicked on "Want it".

Niall said...

It does rather show the rapid development nature of mix doesn't it? One bind variable only (I think) - a constraint called VALIDATES_UNIQUENESS (better than SYSXXXX I admit) which doesn't indicate what needs to be unique

Anonymous said...

Oops. Not using bind variables AND showing the SQL statement in the error. That's just asking for SQL Injection....

Jake said...

@HunterX: I think maybe you multi-clicked on "Want It" :) This is the fix we made to close the hole that Topper found on voting.

I'm told this message has been cleaned up and is waiting for deployment.

Mix isn't perfect, but then again, what really is? We do what we can on a shoestring.

Jake said...

This is fixed in production now. Thanks for reporting it.