There are still some database injections that are possible in MongoDB (although they definitely tend to be less common due to the query language not being text-based). The most common type is when someone directly uses the data from a quest in the query without checking the type; for example, if you have a query that says "delete the user with id ____" and then pass in the id directly from the POST request without checking the type, someone could make a request with a body of `{ "$nin: [] }` (i.e. "not in the empty array"), which would then delete every user in the database. The fix, in this case, is just to check the type of the request data before serializing it into the query; in the example above, you could just return an error if you get anything other than a single user id.
Sorry, I made a stupid joke. Thanks for teaching me something here, this is more than I deserve.
Here, take my upvote. Can’t remember the last time someone seemed to genuinely apologize, explain what act they’re apologizing for, acknowledges their knowledge gaps and seems to actually thank their corrector, all the while sprinkling the comment with a hint of self-deprecation…
This is why things like "/s" are useful.
I also didn't understand that you were making a joke, and was sitting here wondering how using a different type of database would solve this kind of problem.
Similar to the sibling comments, I genuinely didn't realize you were joking either (although looking back now, it definitely seems more obvious!). Either way, I tend to be in the minority that doesn't mind jokes on Hacker News, so I'll give you an upvote as well