maybe this is a nonsense question ... but I got a little lost in Typo3 security
I have my own extension, with an action -> list that has a "keyword" search field in the frontend
<f:form action = "list">
<f:form.textfield name = "keyword" />
<f:form submit value "search">
</f:form>
In my repository, I wrote some code :
class MyRepository extends \TYPO3\CMS\Extbase\Persistence\Repository
{
public function findByFilters(string $keyword)
{
$query = $this->createQuery();
if (isset($keyword) && strlen($keyword) > 0) {
$constraints[] = $query->like('nome_corso', '%' . $keyword . '%');
}
/* other constraints[] */
$query->matching($query->logicalAnd($constraints));
$result = $query->execute();
return ($result);
}
}
QUESTION : Now, i've got a "wildcard" $keyword" and i want avoid sql injection.
Typo3 Manuals suggest to abandon individual database query, and adopt QueryBuilder with createNamedParameter.
Is it really necessary to abandon the individual Query databases derived from the Repository class, and migrate to QueryBuilder, in order to avoid sql injection, or is it possible to set createNamedParameter directly in the query object derived from Repository class?