@alanonai: Engineering for Vibe Coders: SQL Injection A lot of vibe-coded apps are vulnerable to something called SQL injection. Here is how it happens. You take user input and drop it directly into a database query. It works fine with normal input. But if someone sends input that includes SQL code, your database will execute it. That means instead of checking a password, it might return every user. Or bypass authentication completely. The scary part is how simple this is to prevent. You just use parameterized queries. That keeps your query structure fixed and treats user input as data, not code. No guessing. No escaping. Just safe by design. If your app builds SQL queries from user input, it is not just a bug. It is a security risk. Link in comments #ai #vibecoding #coding #programming #security

Alan on AI
Alan on AI
Open In TikTok:
Region: US
Monday 20 April 2026 14:49:56 GMT
39462
2772
53
132

Music

Download

Comments

44_che
44_che :
Where is the link to your book
2026-09-10 16:03:14
1
codyd92
CodyD :
Just tell claude you want strong security, then security for the security. it lays out what he talked about and more. it can work well as long as you are competent
2026-05-11 21:25:10
10
black.beans726
black beans :
Sql injection cant happen if the server doesnt execute raw sql. There are libraries built to avoid this issue. Sqlalchemy, etc…
2026-04-29 03:15:04
4
anoneous_
Anoneous :
This is not for those using node.js.
2026-04-21 14:44:12
1
xyvmain
xyvmain :
wow so people really just ship whatever the ai outputs without a second thought. I mean I call myself a vibecoder but I just use it to spin up prototypes or snippets speed up the process even on snippets frontier models like Claude 4.6 still hallucinate
2026-05-16 04:10:03
1
devintrippie
Trippie Dev :
I had someone comment on a comment of mine saying my website was susceptible to sql injection attack. I’ve been in software development for 20+ years now. It’s really disappointing too see all these people who think they are master developers and hackers but actually don’t know anything. The guy was completely wrong and my website wasn’t susceptible to sql injection because it uses firebase. But he didn’t know that, he just asked his ai to scrape my site. All my sites though are disallowing ai bots to scrape my site so that means their bots have no idea what my site has. People are talking out their a’s these days and it’s really frustrating too see
2026-04-20 16:09:51
6
ashenbot
Ashen :
ty for this
2026-05-15 16:11:37
1
trythisthingnow
trythisthingnow :
thanks for tips!
2026-04-28 16:18:36
1
umarqq_
Umar :
Based off the current era of AI, what would you say is the best way to get into software engineering? I’m currently trying to get in SWE and learning Python at the moment.
2026-04-20 17:13:19
8
shankaholic6
Shankaholic :
you sir will be my savior before I launch! thank you
2026-04-20 20:38:16
2
ahmedramzin
Ahmed Ramzin :
where is the link
2026-06-02 22:53:37
4
weoutherenv
Keith Davis :
Helpful! Great content.
2026-04-20 21:53:07
2
silverchromehearts
s :
is parameterized queries and input validation enough?
2026-04-24 04:26:40
3
kevinlcarlson
Ravings :
Always sanitize inputs
2026-04-20 22:14:51
2
felaris.rick
ʙʙㅤᴀʟᴘʜᴀㅤ×͜× :
thanks Alan
2026-06-13 18:28:16
1
ummmmchris90
Ummchrisdummy :
That’s why you install the ooba superpowers skill set in Claude.
2026-04-21 02:28:32
1
dibbiedap
Davhu :
Go get your food bro
2026-05-25 19:08:56
1
shendiill
sh3ndll :
Hi im making a PWA wrapped as an App using lovable can anybody help i hit a brickwalll 💯
2026-04-22 07:45:52
2
trenthall6
Trent Hall :
Alan I've been closecto one of your day one followers you've helped me a lot this semester
2026-04-20 17:09:36
2
zepirrt
Potato :
in my experience ai is not using raw SQL commands, most of the time people use supabase, and when it doesn't, its using prepared statements
2026-04-21 12:14:01
3
its.nate7
ItsMe :
I've been making a Flask app with sqlite for fun, and Claude actually had me use parameterized queries unprompted. however, I knew to check for it because of past coursework doing SQL injection (maybe I got lucky)
2026-04-21 08:05:28
2
jedipetercodes
Peter | Tech | AI | Gaming :
Didn’t someone manage to inject themselves into the early access list at TSA or something with this last year? Or am I misremembering?
2026-04-21 05:43:16
0
aaronmuscles
AaronMuscles :
My immediate thought is a vibe coder will get a sql injection
2026-04-23 02:35:01
0
md_sghr
HELL YEAH :
Just use an ORM
2026-06-01 17:12:01
0
rvelo1981
rvelo1981 :
Any chance of UK delivery for your book?
2026-04-20 16:42:32
2
To see more videos from user @alanonai, please go to the Tikwm homepage.

Other Videos


About