Просмотр исходного кода

Fixed #26899 -- Documented why RawSQL params is a required parameter.

petedmarsh 8 лет назад
Родитель
Сommit
7bf3ba0d0c
1 измененных файлов с 3 добавлено и 1 удалено
  1. 3 1
      docs/ref/models/expressions.txt

+ 3 - 1
docs/ref/models/expressions.txt

@@ -459,7 +459,9 @@ should avoid them if possible.
 
     You should be very careful to escape any parameters that the user can
     control by using ``params`` in order to protect against :ref:`SQL injection
-    attacks <sql-injection-protection>`.
+    attacks <sql-injection-protection>`. ``params`` is a required argument to
+    force you to acknowledge that you're not interpolating your SQL with user
+    provided data.
 
 .. currentmodule:: django.db.models