63 points

I’m really confused about the arguments around this, being that things like apostrophes and hyphens have special meanings in databases.

Yes, they do… But there are incredibly mature standard practices around how to store and query this type of data so that it isn’t a problem.

Hyphens and apostrophes aren’t uncommon in surnames. Is anyone suggesting banning those?

permalink
report
reply
5 points

Yes, please

permalink
report
parent
reply
38 points
*

"All punctuation will be considered but avoided where possible because street names and addresses, when stored in databases, must meet the standards set out in BS7666.

“This restricts the use of punctuation marks and special characters (e.g. apostrophes, hyphens and ampersands) to avoid potential problems when searching the databases as these characters have specific meanings in computer systems.”

This seems like a dumb line of reasoning. The problem has never been the signs or punctuation in a database. It’s that the people in charge don’t even know what BS7666 even says.

permalink
report
reply
8 points

We have a piece of legacy software and we have to replace certain symbols in text values as there’s manual SQL construction everywhere and none of it uses parameters.

permalink
report
parent
reply
16 points

Ah, yes, I live on “St Mary’ ; DROP TABLE street”

permalink
report
parent
reply
10 points

“we call it Drop street for short”

permalink
report
parent
reply
4 points

I thought it’s the standard’s name that fits the situation, but it appears to be humans at a blame as usual

permalink
report
parent
reply
24 points

How did they ask all these random people and not bother to ask a single software engineer?

“Hi is this excuse real, or is it just a sign of an inappropriate relationship between the local council and a dodgy software company that pays more dividends than developers? Oh it’s the latter? Okay, thanks.”

permalink
report
reply
23 points
*

Wait, is this about SQL injection? Are they admitting that If I paste a piece of paper that says '; drop table streets; -- over their street sign it’ll fuck all their shit up?

If so, this is not a problem that should be fixed by changing the street signs.

Or is the problem that they’ve got people with limited technical skill manually constructing SQL queries to search these “geographical databases” and not knowing how to properly escape them?

Or did some intern developer neglect to use a parameterized query and something broke and the management chain at the North Yorkshire Council who don’t even know what pebkac stands for heard “apostraphies are the problem?”

Maybe they’ve got some image recognition thing on their mail trucks and the apostrophies mess up the otherwise-monospace letter spacing?

Whatever the case, the whole idea of taking the apostrophies off the signs seems ridiculous to me.

permalink
report
reply
20 points
*

So North Yorkshire Council just announced to the whole world that its systems are vulnerable to SQL injection and it’s easier to replace the signs than to fix the software?

permalink
report
reply

Programming

!programming@programming.dev

Create post

Welcome to the main community in programming.dev! Feel free to post anything relating to programming here!

Cross posting is strongly encouraged in the instance. If you feel your post or another person’s post makes sense in another community cross post into it.

Hope you enjoy the instance!

Rules

Rules

  • Follow the programming.dev instance rules
  • Keep content related to programming in some way
  • If you’re posting long videos try to add in some form of tldr for those who don’t want to watch videos

Wormhole

Follow the wormhole through a path of communities !webdev@programming.dev



Community stats

  • 3K

    Monthly active users

  • 1.7K

    Posts

  • 28K

    Comments