23장. Security
application role 최소 권한, host restriction, TLS, secret rotation, audit, at-rest encryption을 둔다. dynamic privilege와 DEFINER object를 검토한다. root remote 접속을 막는다.
SQL injection은 parameterized query로 막고 DB firewall만 믿지 않는다.
WEBBOOK CHAPTER
application role 최소 권한, host restriction, TLS, secret rotation, audit, at-rest encryption을 둔다. dynamic privilege와 DEFINER object를 검토한다. root remote 접속을 막는다.
SQL injection은 parameterized query로 막고 DB firewall만 믿지 않는다.