We used a function like findOne() (I don't recall exactly). It looked like this:
$resetTokens->findOne($GET['password-reset-token']);
The issue was that findOne would accept wildcards, so one could use ?password-reset-token=% in the URL and reset the password of any random users.
This seems like a pretty basic thing to fix, but then I only have your snippet to go by.
If an ORM/builder casually puts =/IS and LIKE in the same method, don’t touch it.
The snippet also validates request inputs, so clearly it doesn't assume that inputs are safe.
If an app stands the stress test against say for example this comprehensive list(1), it can consider itself somewhat safe or at least benchmarked. Otherwise, only vague and unsubstantiated claims, which does not help PHP nor any other programming language or framework.
i.e. $request->query(‘password-reset-token’);
I'm looking for advice on how Rails vs Laravel compare (as I'll have to pick one of them soon for a project). Assuming the same knowledge and familiarity on both of them, why would you prefer Rails over Laravel? Thanks!
I don’t think there is anything Rails can do that Laravel cannot and wise versa.
It’s about taste.
I think Rails + hotwire hit the sweetspot for me!
Of course, this can be a double edged sword if you aren't comfortable in the language yet.