diff --git a/test_security_fix.py b/test_security_fix.py index 5195286..edf9c39 100644 --- a/test_security_fix.py +++ b/test_security_fix.py @@ -1,6 +1,2 @@ -# Test file for security fix demonstration -def get_user_data(user_id): - # Vulnerable: SQL injection - query = f"SELECT * FROM users WHERE id = '{user_id}'" - return db.execute(query) - + query = "SELECT * FROM users WHERE id = %s" + return db.execute(query, (user_id,)) \ No newline at end of file