Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The paper is just describing common sense stuff: using eval() on user input and passing user input directly to a database.


With everything node.js provides, I can't understand why someone would use eval()... Specially with user input.


Of course they wouldn't. "Node.js" and "NoSQL" appear in the title of this article merely to get people to click the link.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: