問題文
A code reviewer looks at a stored procedure in an app that builds a SQL string from a procedure argument and runs it. What does the framework's guidance say about this?
選択肢
- The security scan rejects the version automatically, so no manual review of this particular pattern is needed before publishing it.
- It is acceptable because the app cannot reach the consumer's own objects, so the worst case is confined to data the consumer already sees.
- It is acceptable if the procedure uses restricted caller's rights, because that limits the statement to the caller's privileges.
- Every SQL command that takes user input should use bound parameters, because all procedures in an app run as the application and have access to everything inside it.