diff --git a/app/vulnerable_sql.py b/app/vulnerable_sql.py new file mode 100644 index 00000000..00a3839b --- /dev/null +++ b/app/vulnerable_sql.py @@ -0,0 +1,4 @@ +def get_user_by_username(self, username: str): + query = text("SELECT * FROM users WHERE username = :username") + result = self.db.execute(query, {"username": username}) + return result.fetchone() \ No newline at end of file