{"id":84251,"date":"2024-11-17T13:19:24","date_gmt":"2024-11-17T09:49:24","guid":{"rendered":"https:\/\/nabfollower.com\/blog\/prevent-sql-injection-in-restful-apis-a-comprehensive-guide-5e6\/"},"modified":"2024-11-17T13:19:24","modified_gmt":"2024-11-17T09:49:24","slug":"prevent-sql-injection-in-restful-apis-a-comprehensive-guide-5e6","status":"publish","type":"post","link":"https:\/\/nabfollower.com\/blog\/prevent-sql-injection-in-restful-apis-a-comprehensive-guide-5e6\/","title":{"rendered":"\u062c\u0644\u0648\u06af\u06cc\u0631\u06cc \u0627\u0632 \u062a\u0632\u0631\u06cc\u0642 SQL \u062f\u0631 API \u0647\u0627\u06cc RESTful: \u0631\u0627\u0647\u0646\u0645\u0627\u06cc \u062c\u0627\u0645\u0639"},"content":{"rendered":"<p>Summarize this content to 400 words in Persian Lang <\/p>\n<p>  \u062f\u0631\u06a9 SQL Injection (SQLi) \u062f\u0631 RESTful API<\/p>\n<p>SQL Injection (SQLi) \u06cc\u06a9\u06cc \u0627\u0632 \u0631\u0627\u06cc\u062c\u200c\u062a\u0631\u06cc\u0646 \u0622\u0633\u06cc\u0628\u200c\u067e\u0630\u06cc\u0631\u06cc\u200c\u0647\u0627 \u062f\u0631 \u0628\u0631\u0646\u0627\u0645\u0647\u200c\u0647\u0627\u06cc \u06a9\u0627\u0631\u0628\u0631\u062f\u06cc \u0648\u0628 \u0627\u0633\u062a \u06a9\u0647 API\u0647\u0627\u06cc RESTful \u0631\u0627 \u0628\u0631\u0627\u06cc \u0627\u0633\u062a\u062e\u0631\u0627\u062c \u0627\u0637\u0644\u0627\u0639\u0627\u062a \u062d\u0633\u0627\u0633 \u06cc\u0627 \u0628\u0647 \u062e\u0637\u0631 \u0627\u0646\u062f\u0627\u062e\u062a\u0646 \u0633\u06cc\u0633\u062a\u0645\u200c\u0647\u0627 \u0647\u062f\u0641 \u0642\u0631\u0627\u0631 \u0645\u06cc\u200c\u062f\u0647\u062f. API\u0647\u0627\u06cc REST \u06a9\u0647 \u0628\u0631 \u0645\u062f\u06cc\u0631\u06cc\u062a \u0646\u0627\u062f\u0631\u0633\u062a \u0648\u0631\u0648\u062f\u06cc \u06a9\u0627\u0631\u0628\u0631 \u0645\u062a\u06a9\u06cc \u0647\u0633\u062a\u0646\u062f\u060c \u0627\u0647\u062f\u0627\u0641 \u0627\u0635\u0644\u06cc \u0645\u0647\u0627\u062c\u0645\u0627\u0646 \u0647\u0633\u062a\u0646\u062f.  <\/p>\n<p>\u062f\u0631 \u0627\u06cc\u0646 \u0648\u0628\u0644\u0627\u06af\u060c SQLi\u060c \u062a\u0623\u062b\u06cc\u0631 \u0622\u0646 \u0628\u0631 API\u0647\u0627\u06cc RESTful\u060c \u062a\u06a9\u0646\u06cc\u06a9\u200c\u0647\u0627\u06cc \u067e\u06cc\u0634\u06af\u06cc\u0631\u06cc\u060c \u0648 \u0646\u062d\u0648\u0647 \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0627\u0632 \u0627\u0628\u0632\u0627\u0631 \u0631\u0627\u06cc\u06af\u0627\u0646 \u0628\u0631\u0631\u0633\u06cc \u0627\u0645\u0646\u06cc\u062a \u0648\u0628\u200c\u0633\u0627\u06cc\u062a \u0645\u0627 \u0628\u0631\u0627\u06cc \u0627\u0631\u0632\u06cc\u0627\u0628\u06cc API\u0647\u0627\u06cc \u062e\u0648\u062f \u062f\u0631 \u0628\u0631\u0627\u0628\u0631 \u0622\u0633\u06cc\u0628\u200c\u067e\u0630\u06cc\u0631\u06cc\u200c\u0647\u0627\u06cc\u06cc \u0645\u0627\u0646\u0646\u062f SQL Injection \u0631\u0627 \u0628\u0631\u0631\u0633\u06cc \u062e\u0648\u0627\u0647\u06cc\u0645 \u06a9\u0631\u062f.  <\/p>\n<p>  SQL Injection \u062f\u0631 RESTful API \u0686\u06cc\u0633\u062a\u061f<\/p>\n<p>SQL Injection \u0632\u0645\u0627\u0646\u06cc \u0627\u062a\u0641\u0627\u0642 \u0645\u06cc \u0627\u0641\u062a\u062f \u06a9\u0647 \u0648\u0631\u0648\u062f\u06cc \u0645\u062e\u0631\u0628 \u0628\u0647 \u0639\u0646\u0648\u0627\u0646 \u0628\u062e\u0634\u06cc \u0627\u0632 \u06cc\u06a9 \u067e\u0631\u0633 \u0648 \u062c\u0648\u06cc SQL \u0627\u062c\u0631\u0627 \u0634\u0648\u062f. \u062f\u0631 API \u0647\u0627\u06cc RESTful\u060c \u0645\u0647\u0627\u062c\u0645\u0627\u0646 \u0627\u0632 \u0646\u0642\u0627\u0637 \u067e\u0627\u06cc\u0627\u0646\u06cc \u0622\u0633\u06cc\u0628 \u067e\u0630\u06cc\u0631 \u0628\u0631\u0627\u06cc \u062f\u0648\u0631 \u0632\u062f\u0646 \u0627\u062d\u0631\u0627\u0632 \u0647\u0648\u06cc\u062a\u060c \u0628\u0627\u0632\u06cc\u0627\u0628\u06cc \u062f\u0627\u062f\u0647 \u0647\u0627\u06cc \u062d\u0633\u0627\u0633 \u06cc\u0627 \u067e\u0627\u06cc\u06af\u0627\u0647 \u062f\u0627\u062f\u0647 \u0647\u0627\u06cc \u062e\u0631\u0627\u0628 \u0633\u0648\u0621 \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0645\u06cc \u06a9\u0646\u0646\u062f.  <\/p>\n<p>  \u062a\u0632\u0631\u06cc\u0642 SQL \u0686\u06af\u0648\u0646\u0647 \u06a9\u0627\u0631 \u0645\u06cc \u06a9\u0646\u062f\u061f<\/p>\n<p>\u0627\u06cc\u0646 \u0646\u0642\u0637\u0647 \u067e\u0627\u06cc\u0627\u0646\u06cc \u0622\u0633\u06cc\u0628 \u067e\u0630\u06cc\u0631 \u0631\u0627 \u062f\u0631 \u0646\u0638\u0631 \u0628\u06af\u06cc\u0631\u06cc\u062f:<\/p>\n<p>from flask import Flask, request<br \/>\nimport sqlite3<\/p>\n<p>app = Flask(__name__)<\/p>\n<p>@app.route(&#8216;\/users&#8217;, methods=[&#8216;GET&#8217;])<br \/>\ndef get_user():<br \/>\n    user_id = request.args.get(&#8216;id&#8217;)<br \/>\n    conn = sqlite3.connect(&#8216;database.db&#8217;)<br \/>\n    cursor = conn.cursor()<br \/>\n    query = f&#8221;SELECT * FROM users WHERE id = {user_id};&#8221;<br \/>\n    cursor.execute(query)<br \/>\n    user = cursor.fetchone()<br \/>\n    return {&#8216;user&#8217;: user}<\/p>\n<p>if __name__ == &#8216;__main__&#8217;:<br \/>\n    app.run()<\/p>\n<p>    \u0648\u0627\u0631\u062f \u062d\u0627\u0644\u062a \u062a\u0645\u0627\u0645 \u0635\u0641\u062d\u0647 \u0634\u0648\u06cc\u062f<\/p>\n<p>    \u0627\u0632 \u062d\u0627\u0644\u062a \u062a\u0645\u0627\u0645 \u0635\u0641\u062d\u0647 \u062e\u0627\u0631\u062c \u0634\u0648\u06cc\u062f<\/p>\n<p>\u0627\u06af\u0631 \u0645\u0647\u0627\u062c\u0645 \u0627\u0631\u0633\u0627\u0644 \u06a9\u0646\u062f id=1 OR 1=1\u060c \u067e\u0631\u0633 \u0648 \u062c\u0648 \u0645\u06cc \u0634\u0648\u062f:<\/p>\n<p>SELECT * FROM users WHERE id = 1 OR 1=1;<\/p>\n<p>    \u0648\u0627\u0631\u062f \u062d\u0627\u0644\u062a \u062a\u0645\u0627\u0645 \u0635\u0641\u062d\u0647 \u0634\u0648\u06cc\u062f<\/p>\n<p>    \u0627\u0632 \u062d\u0627\u0644\u062a \u062a\u0645\u0627\u0645 \u0635\u0641\u062d\u0647 \u062e\u0627\u0631\u062c \u0634\u0648\u06cc\u062f<\/p>\n<p>\u0627\u06cc\u0646 \u067e\u0631\u0633 \u0648 \u062c\u0648 \u0647\u0645\u0647 \u0631\u062f\u06cc\u0641 \u0647\u0627 \u0631\u0627 \u0628\u0627\u0632\u06cc\u0627\u0628\u06cc \u0645\u06cc \u06a9\u0646\u062f \u0648 \u062f\u0627\u062f\u0647 \u0647\u0627\u06cc \u062d\u0633\u0627\u0633 \u0631\u0627 \u062f\u0631 \u0645\u0639\u0631\u0636 \u0646\u0645\u0627\u06cc\u0634 \u0642\u0631\u0627\u0631 \u0645\u06cc \u062f\u0647\u062f.  <\/p>\n<p>  \u062c\u0644\u0648\u06af\u06cc\u0631\u06cc \u0627\u0632 \u062a\u0632\u0631\u06cc\u0642 SQL \u062f\u0631 API \u0647\u0627\u06cc RESTful<\/p>\n<p>1. \u0627\u0632 \u067e\u0631\u0633 \u0648 \u062c\u0648\u0647\u0627\u06cc \u067e\u0627\u0631\u0627\u0645\u062a\u0631\u06cc \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u06a9\u0646\u06cc\u062f\u067e\u0631\u0633 \u0648 \u062c\u0648\u0647\u0627\u06cc \u067e\u0627\u0631\u0627\u0645\u062a\u0631\u06cc \u062a\u0636\u0645\u06cc\u0646 \u0645\u06cc \u06a9\u0646\u0646\u062f \u06a9\u0647 \u0648\u0631\u0648\u062f\u06cc \u0628\u0647 \u0639\u0646\u0648\u0627\u0646 \u062f\u0627\u062f\u0647 \u062f\u0631 \u0646\u0638\u0631 \u06af\u0631\u0641\u062a\u0647 \u0645\u06cc \u0634\u0648\u062f\u060c \u0646\u0647 \u06a9\u062f \u0627\u062c\u0631\u0627\u06cc\u06cc. \u062f\u0631 \u0627\u06cc\u0646\u062c\u0627 \u06cc\u06a9 \u0646\u0633\u062e\u0647 \u0627\u0645\u0646 \u062a\u0631 \u0627\u0632 \u06a9\u062f \u0628\u0627\u0644\u0627 \u0622\u0645\u062f\u0647 \u0627\u0633\u062a:<\/p>\n<p>@app.route(&#8216;\/users&#8217;, methods=[&#8216;GET&#8217;])<br \/>\ndef get_user():<br \/>\n    user_id = request.args.get(&#8216;id&#8217;)<br \/>\n    conn = sqlite3.connect(&#8216;database.db&#8217;)<br \/>\n    cursor = conn.cursor()<br \/>\n    query = &#8220;SELECT * FROM users WHERE id = ?;&#8221;<br \/>\n    cursor.execute(query, (user_id,))<br \/>\n    user = cursor.fetchone()<br \/>\n    return {&#8216;user&#8217;: user}<\/p>\n<p>    \u0648\u0627\u0631\u062f \u062d\u0627\u0644\u062a \u062a\u0645\u0627\u0645 \u0635\u0641\u062d\u0647 \u0634\u0648\u06cc\u062f<\/p>\n<p>    \u0627\u0632 \u062d\u0627\u0644\u062a \u062a\u0645\u0627\u0645 \u0635\u0641\u062d\u0647 \u062e\u0627\u0631\u062c \u0634\u0648\u06cc\u062f<\/p>\n<p>2. \u0627\u0639\u062a\u0628\u0627\u0631 \u0648\u0631\u0648\u062f\u06cc \u06a9\u0627\u0631\u0628\u0631\u0647\u0645\u06cc\u0634\u0647 \u0648\u0631\u0648\u062f\u06cc \u0631\u0627 \u0628\u0631\u0627\u06cc \u0645\u0637\u0627\u0628\u0642\u062a \u0628\u0627 \u0642\u0627\u0644\u0628\u200c\u0647\u0627\u06cc \u0645\u0648\u0631\u062f \u0627\u0646\u062a\u0638\u0627\u0631 \u062a\u0623\u06cc\u06cc\u062f \u06a9\u0646\u06cc\u062f. \u0628\u0647 \u0639\u0646\u0648\u0627\u0646 \u0645\u062b\u0627\u0644:<\/p>\n<p>def validate_id(user_id):<br \/>\n    if not user_id.isdigit():<br \/>\n        raise ValueError(&#8220;Invalid user ID&#8221;)<\/p>\n<p>    \u0648\u0627\u0631\u062f \u062d\u0627\u0644\u062a \u062a\u0645\u0627\u0645 \u0635\u0641\u062d\u0647 \u0634\u0648\u06cc\u062f<\/p>\n<p>    \u0627\u0632 \u062d\u0627\u0644\u062a \u062a\u0645\u0627\u0645 \u0635\u0641\u062d\u0647 \u062e\u0627\u0631\u062c \u0634\u0648\u06cc\u062f<\/p>\n<p>3. \u0628\u0647\u062a\u0631\u06cc\u0646 \u0631\u0648\u0634 \u0647\u0627\u06cc \u0627\u0645\u0646\u06cc\u062a\u06cc API \u0631\u0627 \u067e\u06cc\u0627\u062f\u0647 \u0633\u0627\u0632\u06cc \u06a9\u0646\u06cc\u062f  <\/p>\n<p>\u0645\u062d\u062f\u0648\u062f \u06a9\u0631\u062f\u0646 \u062f\u0627\u062f\u0647 \u0647\u0627\u06cc \u062f\u0631 \u0645\u0639\u0631\u0636: \u0627\u0632 \u0628\u0627\u0632\u06af\u0631\u062f\u0627\u0646\u062f\u0646 \u06a9\u0644 \u0648\u0631\u0648\u062f\u06cc \u0647\u0627\u06cc \u067e\u0627\u06cc\u06af\u0627\u0647 \u062f\u0627\u062f\u0647 \u062e\u0648\u062f\u062f\u0627\u0631\u06cc \u06a9\u0646\u06cc\u062f.<\/p>\n<p>\u0627\u0632 \u0647\u062f\u0631\u0647\u0627\u06cc \u0627\u0645\u0646\u06cc\u062a\u06cc \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u06a9\u0646\u06cc\u062f: \u067e\u06cc\u0627\u062f\u0647 \u0633\u0627\u0632\u06cc \u0647\u062f\u0631 \u0645\u0627\u0646\u0646\u062f Content-Security-Policy.<\/p>\n<p>\u0641\u0639\u0627\u0644 \u06a9\u0631\u062f\u0646 \u06af\u0632\u0627\u0631\u0634 API: \u0646\u0638\u0627\u0631\u062a \u0628\u0631 \u062f\u0631\u062e\u0648\u0627\u0633\u062a \u0647\u0627 \u0628\u0631\u0627\u06cc \u062a\u0634\u062e\u06cc\u0635 \u0627\u0644\u06af\u0648\u0647\u0627\u06cc \u063a\u06cc\u0631\u0639\u0627\u062f\u06cc.<\/p>\n<p>  \u0627\u0632 \u062c\u0633\u062a\u062c\u0648\u06af\u0631 \u0627\u0645\u0646\u06cc\u062a \u0648\u0628 \u0633\u0627\u06cc\u062a \u0631\u0627\u06cc\u06af\u0627\u0646 \u0628\u0631\u0627\u06cc \u0645\u062d\u0627\u0641\u0638\u062a \u0627\u0632 SQLi \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u06a9\u0646\u06cc\u062f<\/p>\n<p>\u0627\u0628\u0632\u0627\u0631 \u0628\u0631\u0631\u0633\u06cc \u0627\u0645\u0646\u06cc\u062a \u0648\u0628 \u0633\u0627\u06cc\u062a \u0645\u0627 \u0634\u0646\u0627\u0633\u0627\u06cc\u06cc \u0622\u0633\u06cc\u0628 \u067e\u0630\u06cc\u0631\u06cc \u0647\u0627\u06cc \u062a\u0632\u0631\u06cc\u0642 SQL \u0631\u0627 \u0633\u0627\u062f\u0647 \u0645\u06cc \u06a9\u0646\u062f. \u062f\u0631 \u0632\u06cc\u0631 \u0646\u0645\u0648\u0646\u0647 \u0627\u06cc \u0627\u0632 \u0627\u0633\u06a9\u0631\u06cc\u0646 \u0634\u0627\u062a \u06af\u0632\u0627\u0631\u0634 \u0627\u0632 \u0627\u0628\u0632\u0627\u0631 \u0645\u0627 \u0628\u0631\u0627\u06cc \u06a9\u0645\u06a9 \u0628\u0647 \u062a\u062c\u0633\u0645 \u06cc\u0627\u0641\u062a\u0647 \u0647\u0627\u06cc \u0622\u0646 \u0622\u0648\u0631\u062f\u0647 \u0634\u062f\u0647 \u0627\u0633\u062a:  <\/p>\n<p>\u0627\u0632 \u0627\u06cc\u0646 \u0627\u0628\u0632\u0627\u0631 \u0628\u0631\u0627\u06cc \u0627\u0633\u06a9\u0646 \u0646\u0642\u0627\u0637 \u067e\u0627\u06cc\u0627\u0646\u06cc RESTful API \u0648 \u0627\u06cc\u0645\u0646 \u0633\u0627\u0632\u06cc \u0628\u0631\u0646\u0627\u0645\u0647 \u062e\u0648\u062f \u0642\u0628\u0644 \u0627\u0632 \u0633\u0648\u0621 \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0645\u0647\u0627\u062c\u0645\u0627\u0646 \u0627\u0632 \u0647\u0631\u06af\u0648\u0646\u0647 \u062d\u0641\u0631\u0647 \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u06a9\u0646\u06cc\u062f.  <\/p>\n<p>\u0639\u0644\u0627\u0648\u0647 \u0628\u0631 \u0627\u06cc\u0646\u060c \u062f\u0631 \u0627\u06cc\u0646\u062c\u0627 \u06cc\u06a9 \u0639\u06a9\u0633 \u0641\u0648\u0631\u06cc \u0627\u0632 \u0635\u0641\u062d\u0647 \u0627\u0635\u0644\u06cc \u0627\u0628\u0632\u0627\u0631 \u0645\u0627 \u0628\u0631\u0627\u06cc \u0646\u0634\u0627\u0646 \u062f\u0627\u062f\u0646 \u0633\u0647\u0648\u0644\u062a \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0627\u0632 \u0622\u0646 \u0622\u0648\u0631\u062f\u0647 \u0634\u062f\u0647 \u0627\u0633\u062a:  <\/p>\n<p>  \u0686\u0631\u0627 \u0631\u0648\u06cc \u067e\u06cc\u0634\u06af\u06cc\u0631\u06cc \u0627\u0632 SQLi \u062f\u0631 API\u0647\u0627 \u062a\u0645\u0631\u06a9\u0632 \u06a9\u0646\u06cc\u0645\u061f<\/p>\n<p>\u0631\u0634\u062f \u06cc\u06a9\u067e\u0627\u0631\u0686\u0647 \u0633\u0627\u0632\u06cc API: API \u0647\u0627 \u0627\u063a\u0644\u0628 \u062f\u0627\u062f\u0647 \u0647\u0627\u06cc \u062d\u0633\u0627\u0633 \u0631\u0627 \u0645\u062f\u06cc\u0631\u06cc\u062a \u0645\u06cc \u06a9\u0646\u0646\u062f \u0648 \u0622\u0646\u0647\u0627 \u0631\u0627 \u0628\u0647 \u0627\u0647\u062f\u0627\u0641 \u062c\u0630\u0627\u0628\u06cc \u062a\u0628\u062f\u06cc\u0644 \u0645\u06cc \u06a9\u0646\u0646\u062f.<\/p>\n<p>\u0634\u062f\u062a \u0628\u0627\u0644\u0627: \u062d\u0645\u0644\u0627\u062a SQLi \u0645\u06cc \u062a\u0648\u0627\u0646\u062f \u0645\u0646\u062c\u0631 \u0628\u0647 \u0646\u0642\u0636 \u062f\u0627\u062f\u0647 \u0647\u0627 \u0648 \u0636\u0631\u0631\u0647\u0627\u06cc \u0645\u0627\u0644\u06cc \u0634\u0648\u062f.<\/p>\n<p>\u0646\u06cc\u0627\u0632\u0647\u0627\u06cc \u0627\u0646\u0637\u0628\u0627\u0642: \u0627\u0633\u062a\u0627\u0646\u062f\u0627\u0631\u062f\u0647\u0627\u06cc\u06cc \u0645\u0627\u0646\u0646\u062f OWASP \u0648 PCI DSS \u062f\u0641\u0627\u0639 \u0642\u0648\u06cc SQLi \u0631\u0627 \u0627\u0644\u0632\u0627\u0645\u06cc \u0645\u06cc \u06a9\u0646\u0646\u062f.<\/p>\n<p>  \u0627\u0641\u06a9\u0627\u0631 \u0646\u0647\u0627\u06cc\u06cc<\/p>\n<p>\u062c\u0644\u0648\u06af\u06cc\u0631\u06cc \u0627\u0632 \u062a\u0632\u0631\u06cc\u0642 SQL \u062f\u0631 API \u0647\u0627\u06cc RESTful \u0628\u0647 \u0627\u0642\u062f\u0627\u0645\u0627\u062a \u067e\u06cc\u0634\u06af\u06cc\u0631\u0627\u0646\u0647 \u0646\u06cc\u0627\u0632 \u062f\u0627\u0631\u062f\u060c \u0627\u0632 \u0645\u062f\u06cc\u0631\u06cc\u062a \u0635\u062d\u06cc\u062d \u0648\u0631\u0648\u062f\u06cc \u062a\u0627 \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0627\u0632 \u0627\u0628\u0632\u0627\u0631\u0647\u0627\u06cc \u0627\u0645\u0646\u06cc\u062a\u06cc. \u0628\u0627 \u062a\u062c\u0632\u06cc\u0647 \u0648 \u062a\u062d\u0644\u06cc\u0644 API \u0647\u0627\u06cc \u062e\u0648\u062f \u0628\u0627 \u0645\u0627 \u0634\u0631\u0648\u0639 \u06a9\u0646\u06cc\u062f \u0627\u0628\u0632\u0627\u0631 \u0628\u0631\u0631\u0633\u06cc \u0627\u0645\u0646\u06cc\u062a \u0648\u0628 \u0633\u0627\u06cc\u062a \u0628\u0631\u0627\u06cc \u0627\u0631\u0632\u06cc\u0627\u0628\u06cc \u0622\u0633\u06cc\u0628\u200c\u067e\u0630\u06cc\u0631\u06cc \u0631\u0627\u06cc\u06af\u0627\u0646  <\/p>\n<p>\u0627\u0632 \u0628\u0631\u0646\u0627\u0645\u0647 \u0647\u0627\u06cc \u062e\u0648\u062f \u0645\u062d\u0627\u0641\u0638\u062a \u06a9\u0646\u06cc\u062f\u060c \u0627\u0632 \u062f\u0627\u062f\u0647 \u0647\u0627\u06cc \u062d\u0633\u0627\u0633 \u0645\u062d\u0627\u0641\u0638\u062a \u06a9\u0646\u06cc\u062f \u0648 \u0627\u0645\u0646\u06cc\u062a API \u0631\u0627 \u0627\u0645\u0631\u0648\u0632 \u0627\u0641\u0632\u0627\u06cc\u0634 \u062f\u0647\u06cc\u062f!  <\/p>\n<div data-article-id=\"2107921\" id=\"article-body\">\n<div id=\"ez-toc-container\" class=\"ez-toc-v2_0_85 counter-hierarchy ez-toc-counter-rtl ez-toc-grey ez-toc-container-direction\">\n<div class=\"ez-toc-title-container\">\n<p class=\"ez-toc-title\" style=\"cursor:inherit\">\u0641\u0647\u0631\u0633\u062a \u0645\u0637\u0627\u0644\u0628<\/p>\n<span class=\"ez-toc-title-toggle\"><a href=\"#\" class=\"ez-toc-pull-right ez-toc-btn ez-toc-btn-xs ez-toc-btn-default ez-toc-toggle\" aria-label=\"Toggle Table of Content\"><span class=\"ez-toc-js-icon-con\"><span class=\"\"><span class=\"eztoc-hide\" style=\"display:none;\">Toggle<\/span><span class=\"ez-toc-icon-toggle-span\"><svg style=\"fill: #999;color:#999\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" class=\"list-377408\" width=\"20px\" height=\"20px\" viewBox=\"0 0 24 24\" fill=\"none\"><path d=\"M6 6H4v2h2V6zm14 0H8v2h12V6zM4 11h2v2H4v-2zm16 0H8v2h12v-2zM4 16h2v2H4v-2zm16 0H8v2h12v-2z\" fill=\"currentColor\"><\/path><\/svg><svg style=\"fill: #999;color:#999\" class=\"arrow-unsorted-368013\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"10px\" height=\"10px\" viewBox=\"0 0 24 24\" version=\"1.2\" baseProfile=\"tiny\"><path d=\"M18.2 9.3l-6.2-6.3-6.2 6.3c-.2.2-.3.4-.3.7s.1.5.3.7c.2.2.4.3.7.3h11c.3 0 .5-.1.7-.3.2-.2.3-.5.3-.7s-.1-.5-.3-.7zM5.8 14.7l6.2 6.3 6.2-6.3c.2-.2.3-.5.3-.7s-.1-.5-.3-.7c-.2-.2-.4-.3-.7-.3h-11c-.3 0-.5.1-.7.3-.2.2-.3.5-.3.7s.1.5.3.7z\"\/><\/svg><\/span><\/span><\/span><\/a><\/span><\/div>\n<nav><ul class='ez-toc-list ez-toc-list-level-1 ' ><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-1\" href=\"https:\/\/nabfollower.com\/blog\/prevent-sql-injection-in-restful-apis-a-comprehensive-guide-5e6\/#%D8%AF%D8%B1%DA%A9_SQL_Injection_SQLi_%D8%AF%D8%B1_RESTful_API\" >\u062f\u0631\u06a9 SQL Injection (SQLi) \u062f\u0631 RESTful API<\/a><ul class='ez-toc-list-level-3' ><li class='ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-2\" href=\"https:\/\/nabfollower.com\/blog\/prevent-sql-injection-in-restful-apis-a-comprehensive-guide-5e6\/#SQL_Injection_%D8%AF%D8%B1_RESTful_API_%DA%86%DB%8C%D8%B3%D8%AA%D8%9F\" >SQL Injection \u062f\u0631 RESTful API \u0686\u06cc\u0633\u062a\u061f<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-3\" href=\"https:\/\/nabfollower.com\/blog\/prevent-sql-injection-in-restful-apis-a-comprehensive-guide-5e6\/#%D8%AA%D8%B2%D8%B1%DB%8C%D9%82_SQL_%DA%86%DA%AF%D9%88%D9%86%D9%87_%DA%A9%D8%A7%D8%B1_%D9%85%DB%8C_%DA%A9%D9%86%D8%AF%D8%9F\" >\u062a\u0632\u0631\u06cc\u0642 SQL \u0686\u06af\u0648\u0646\u0647 \u06a9\u0627\u0631 \u0645\u06cc \u06a9\u0646\u062f\u061f<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-4\" href=\"https:\/\/nabfollower.com\/blog\/prevent-sql-injection-in-restful-apis-a-comprehensive-guide-5e6\/#%D8%AC%D9%84%D9%88%DA%AF%DB%8C%D8%B1%DB%8C_%D8%A7%D8%B2_%D8%AA%D8%B2%D8%B1%DB%8C%D9%82_SQL_%D8%AF%D8%B1_API_%D9%87%D8%A7%DB%8C_RESTful\" >\u062c\u0644\u0648\u06af\u06cc\u0631\u06cc \u0627\u0632 \u062a\u0632\u0631\u06cc\u0642 SQL \u062f\u0631 API \u0647\u0627\u06cc RESTful<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-5\" href=\"https:\/\/nabfollower.com\/blog\/prevent-sql-injection-in-restful-apis-a-comprehensive-guide-5e6\/#%D8%A7%D8%B2_%D8%AC%D8%B3%D8%AA%D8%AC%D9%88%DA%AF%D8%B1_%D8%A7%D9%85%D9%86%DB%8C%D8%AA_%D9%88%D8%A8_%D8%B3%D8%A7%DB%8C%D8%AA_%D8%B1%D8%A7%DB%8C%DA%AF%D8%A7%D9%86_%D8%A8%D8%B1%D8%A7%DB%8C_%D9%85%D8%AD%D8%A7%D9%81%D8%B8%D8%AA_%D8%A7%D8%B2_SQLi_%D8%A7%D8%B3%D8%AA%D9%81%D8%A7%D8%AF%D9%87_%DA%A9%D9%86%DB%8C%D8%AF\" >\u0627\u0632 \u062c\u0633\u062a\u062c\u0648\u06af\u0631 \u0627\u0645\u0646\u06cc\u062a \u0648\u0628 \u0633\u0627\u06cc\u062a \u0631\u0627\u06cc\u06af\u0627\u0646 \u0628\u0631\u0627\u06cc \u0645\u062d\u0627\u0641\u0638\u062a \u0627\u0632 SQLi \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u06a9\u0646\u06cc\u062f<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-6\" href=\"https:\/\/nabfollower.com\/blog\/prevent-sql-injection-in-restful-apis-a-comprehensive-guide-5e6\/#%DA%86%D8%B1%D8%A7_%D8%B1%D9%88%DB%8C_%D9%BE%DB%8C%D8%B4%DA%AF%DB%8C%D8%B1%DB%8C_%D8%A7%D8%B2_SQLi_%D8%AF%D8%B1_API%D9%87%D8%A7_%D8%AA%D9%85%D8%B1%DA%A9%D8%B2_%DA%A9%D9%86%DB%8C%D9%85%D8%9F\" >\u0686\u0631\u0627 \u0631\u0648\u06cc \u067e\u06cc\u0634\u06af\u06cc\u0631\u06cc \u0627\u0632 SQLi \u062f\u0631 API\u0647\u0627 \u062a\u0645\u0631\u06a9\u0632 \u06a9\u0646\u06cc\u0645\u061f<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-7\" href=\"https:\/\/nabfollower.com\/blog\/prevent-sql-injection-in-restful-apis-a-comprehensive-guide-5e6\/#%D8%A7%D9%81%DA%A9%D8%A7%D8%B1_%D9%86%D9%87%D8%A7%DB%8C%DB%8C\" >\u0627\u0641\u06a9\u0627\u0631 \u0646\u0647\u0627\u06cc\u06cc<\/a><\/li><\/ul><\/li><\/ul><\/nav><\/div>\n<h2><span class=\"ez-toc-section\" id=\"%D8%AF%D8%B1%DA%A9_SQL_Injection_SQLi_%D8%AF%D8%B1_RESTful_API\"><\/span>\n<p>  \u062f\u0631\u06a9 SQL Injection (SQLi) \u062f\u0631 RESTful API<br \/>\n<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>SQL Injection (SQLi) \u06cc\u06a9\u06cc \u0627\u0632 \u0631\u0627\u06cc\u062c\u200c\u062a\u0631\u06cc\u0646 \u0622\u0633\u06cc\u0628\u200c\u067e\u0630\u06cc\u0631\u06cc\u200c\u0647\u0627 \u062f\u0631 \u0628\u0631\u0646\u0627\u0645\u0647\u200c\u0647\u0627\u06cc \u06a9\u0627\u0631\u0628\u0631\u062f\u06cc \u0648\u0628 \u0627\u0633\u062a \u06a9\u0647 API\u0647\u0627\u06cc RESTful \u0631\u0627 \u0628\u0631\u0627\u06cc \u0627\u0633\u062a\u062e\u0631\u0627\u062c \u0627\u0637\u0644\u0627\u0639\u0627\u062a \u062d\u0633\u0627\u0633 \u06cc\u0627 \u0628\u0647 \u062e\u0637\u0631 \u0627\u0646\u062f\u0627\u062e\u062a\u0646 \u0633\u06cc\u0633\u062a\u0645\u200c\u0647\u0627 \u0647\u062f\u0641 \u0642\u0631\u0627\u0631 \u0645\u06cc\u200c\u062f\u0647\u062f. API\u0647\u0627\u06cc REST \u06a9\u0647 \u0628\u0631 \u0645\u062f\u06cc\u0631\u06cc\u062a \u0646\u0627\u062f\u0631\u0633\u062a \u0648\u0631\u0648\u062f\u06cc \u06a9\u0627\u0631\u0628\u0631 \u0645\u062a\u06a9\u06cc \u0647\u0633\u062a\u0646\u062f\u060c \u0627\u0647\u062f\u0627\u0641 \u0627\u0635\u0644\u06cc \u0645\u0647\u0627\u062c\u0645\u0627\u0646 \u0647\u0633\u062a\u0646\u062f.  <\/p>\n<p>\u062f\u0631 \u0627\u06cc\u0646 \u0648\u0628\u0644\u0627\u06af\u060c SQLi\u060c \u062a\u0623\u062b\u06cc\u0631 \u0622\u0646 \u0628\u0631 API\u0647\u0627\u06cc RESTful\u060c \u062a\u06a9\u0646\u06cc\u06a9\u200c\u0647\u0627\u06cc \u067e\u06cc\u0634\u06af\u06cc\u0631\u06cc\u060c \u0648 \u0646\u062d\u0648\u0647 \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0627\u0632 \u0627\u0628\u0632\u0627\u0631 \u0631\u0627\u06cc\u06af\u0627\u0646 \u0628\u0631\u0631\u0633\u06cc \u0627\u0645\u0646\u06cc\u062a \u0648\u0628\u200c\u0633\u0627\u06cc\u062a \u0645\u0627 \u0628\u0631\u0627\u06cc \u0627\u0631\u0632\u06cc\u0627\u0628\u06cc API\u0647\u0627\u06cc \u062e\u0648\u062f \u062f\u0631 \u0628\u0631\u0627\u0628\u0631 \u0622\u0633\u06cc\u0628\u200c\u067e\u0630\u06cc\u0631\u06cc\u200c\u0647\u0627\u06cc\u06cc \u0645\u0627\u0646\u0646\u062f SQL Injection \u0631\u0627 \u0628\u0631\u0631\u0633\u06cc \u062e\u0648\u0627\u0647\u06cc\u0645 \u06a9\u0631\u062f.  <\/p>\n<h3><span class=\"ez-toc-section\" id=\"SQL_Injection_%D8%AF%D8%B1_RESTful_API_%DA%86%DB%8C%D8%B3%D8%AA%D8%9F\"><\/span>\n<p>  SQL Injection \u062f\u0631 RESTful API \u0686\u06cc\u0633\u062a\u061f<br \/>\n<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>SQL Injection \u0632\u0645\u0627\u0646\u06cc \u0627\u062a\u0641\u0627\u0642 \u0645\u06cc \u0627\u0641\u062a\u062f \u06a9\u0647 \u0648\u0631\u0648\u062f\u06cc \u0645\u062e\u0631\u0628 \u0628\u0647 \u0639\u0646\u0648\u0627\u0646 \u0628\u062e\u0634\u06cc \u0627\u0632 \u06cc\u06a9 \u067e\u0631\u0633 \u0648 \u062c\u0648\u06cc SQL \u0627\u062c\u0631\u0627 \u0634\u0648\u062f. \u062f\u0631 API \u0647\u0627\u06cc RESTful\u060c \u0645\u0647\u0627\u062c\u0645\u0627\u0646 \u0627\u0632 \u0646\u0642\u0627\u0637 \u067e\u0627\u06cc\u0627\u0646\u06cc \u0622\u0633\u06cc\u0628 \u067e\u0630\u06cc\u0631 \u0628\u0631\u0627\u06cc \u062f\u0648\u0631 \u0632\u062f\u0646 \u0627\u062d\u0631\u0627\u0632 \u0647\u0648\u06cc\u062a\u060c \u0628\u0627\u0632\u06cc\u0627\u0628\u06cc \u062f\u0627\u062f\u0647 \u0647\u0627\u06cc \u062d\u0633\u0627\u0633 \u06cc\u0627 \u067e\u0627\u06cc\u06af\u0627\u0647 \u062f\u0627\u062f\u0647 \u0647\u0627\u06cc \u062e\u0631\u0627\u0628 \u0633\u0648\u0621 \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0645\u06cc \u06a9\u0646\u0646\u062f.  <\/p>\n<h3><span class=\"ez-toc-section\" id=\"%D8%AA%D8%B2%D8%B1%DB%8C%D9%82_SQL_%DA%86%DA%AF%D9%88%D9%86%D9%87_%DA%A9%D8%A7%D8%B1_%D9%85%DB%8C_%DA%A9%D9%86%D8%AF%D8%9F\"><\/span>\n<p>  \u062a\u0632\u0631\u06cc\u0642 SQL \u0686\u06af\u0648\u0646\u0647 \u06a9\u0627\u0631 \u0645\u06cc \u06a9\u0646\u062f\u061f<br \/>\n<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>\u0627\u06cc\u0646 \u0646\u0642\u0637\u0647 \u067e\u0627\u06cc\u0627\u0646\u06cc \u0622\u0633\u06cc\u0628 \u067e\u0630\u06cc\u0631 \u0631\u0627 \u062f\u0631 \u0646\u0638\u0631 \u0628\u06af\u06cc\u0631\u06cc\u062f:<\/p>\n<div class=\"highlight js-code-highlight\">\n<pre class=\"highlight python\"><code><span class=\"kn\">from<\/span> <span class=\"n\">flask<\/span> <span class=\"kn\">import<\/span> <span class=\"n\">Flask<\/span><span class=\"p\">,<\/span> <span class=\"n\">request<\/span>\n<span class=\"kn\">import<\/span> <span class=\"n\">sqlite3<\/span>\n\n<span class=\"n\">app<\/span> <span class=\"o\">=<\/span> <span class=\"nc\">Flask<\/span><span class=\"p\">(<\/span><span class=\"n\">__name__<\/span><span class=\"p\">)<\/span>\n\n<span class=\"nd\">@app.route<\/span><span class=\"p\">(<\/span><span class=\"sh\">'<\/span><span class=\"s\">\/users<\/span><span class=\"sh\">'<\/span><span class=\"p\">,<\/span> <span class=\"n\">methods<\/span><span class=\"o\">=<\/span><span class=\"p\">[<\/span><span class=\"sh\">'<\/span><span class=\"s\">GET<\/span><span class=\"sh\">'<\/span><span class=\"p\">])<\/span>\n<span class=\"k\">def<\/span> <span class=\"nf\">get_user<\/span><span class=\"p\">():<\/span>\n    <span class=\"n\">user_id<\/span> <span class=\"o\">=<\/span> <span class=\"n\">request<\/span><span class=\"p\">.<\/span><span class=\"n\">args<\/span><span class=\"p\">.<\/span><span class=\"nf\">get<\/span><span class=\"p\">(<\/span><span class=\"sh\">'<\/span><span class=\"s\">id<\/span><span class=\"sh\">'<\/span><span class=\"p\">)<\/span>\n    <span class=\"n\">conn<\/span> <span class=\"o\">=<\/span> <span class=\"n\">sqlite3<\/span><span class=\"p\">.<\/span><span class=\"nf\">connect<\/span><span class=\"p\">(<\/span><span class=\"sh\">'<\/span><span class=\"s\">database.db<\/span><span class=\"sh\">'<\/span><span class=\"p\">)<\/span>\n    <span class=\"n\">cursor<\/span> <span class=\"o\">=<\/span> <span class=\"n\">conn<\/span><span class=\"p\">.<\/span><span class=\"nf\">cursor<\/span><span class=\"p\">()<\/span>\n    <span class=\"n\">query<\/span> <span class=\"o\">=<\/span> <span class=\"sa\">f<\/span><span class=\"sh\">\"<\/span><span class=\"s\">SELECT * FROM users WHERE id = <\/span><span class=\"si\">{<\/span><span class=\"n\">user_id<\/span><span class=\"si\">}<\/span><span class=\"s\">;<\/span><span class=\"sh\">\"<\/span>\n    <span class=\"n\">cursor<\/span><span class=\"p\">.<\/span><span class=\"nf\">execute<\/span><span class=\"p\">(<\/span><span class=\"n\">query<\/span><span class=\"p\">)<\/span>\n    <span class=\"n\">user<\/span> <span class=\"o\">=<\/span> <span class=\"n\">cursor<\/span><span class=\"p\">.<\/span><span class=\"nf\">fetchone<\/span><span class=\"p\">()<\/span>\n    <span class=\"k\">return<\/span> <span class=\"p\">{<\/span><span class=\"sh\">'<\/span><span class=\"s\">user<\/span><span class=\"sh\">'<\/span><span class=\"p\">:<\/span> <span class=\"n\">user<\/span><span class=\"p\">}<\/span>\n\n<span class=\"k\">if<\/span> <span class=\"n\">__name__<\/span> <span class=\"o\">==<\/span> <span class=\"sh\">'<\/span><span class=\"s\">__main__<\/span><span class=\"sh\">'<\/span><span class=\"p\">:<\/span>\n    <span class=\"n\">app<\/span><span class=\"p\">.<\/span><span class=\"nf\">run<\/span><span class=\"p\">()<\/span>\n<\/code><\/pre>\n<div class=\"highlight__panel js-actions-panel\">\n<div class=\"highlight__panel-action js-fullscreen-code-action\">\n    <svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"20px\" height=\"20px\" viewbox=\"0 0 24 24\" class=\"highlight-action crayons-icon highlight-action--fullscreen-on\"><title>\u0648\u0627\u0631\u062f \u062d\u0627\u0644\u062a \u062a\u0645\u0627\u0645 \u0635\u0641\u062d\u0647 \u0634\u0648\u06cc\u062f<\/title>\n    <path d=\"M16 3h6v6h-2V5h-4V3zM2 3h6v2H4v4H2V3zm18 16v-4h2v6h-6v-2h4zM4 19h4v2H2v-6h2v4z\"\/>\n<\/svg><\/p>\n<p>    <svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"20px\" height=\"20px\" viewbox=\"0 0 24 24\" class=\"highlight-action crayons-icon highlight-action--fullscreen-off\"><title>\u0627\u0632 \u062d\u0627\u0644\u062a \u062a\u0645\u0627\u0645 \u0635\u0641\u062d\u0647 \u062e\u0627\u0631\u062c \u0634\u0648\u06cc\u062f<\/title>\n    <path d=\"M18 7h4v2h-6V3h2v4zM8 9H2V7h4V3h2v6zm10 8v4h-2v-6h6v2h-4zM8 15v6H6v-4H2v-2h6z\"\/>\n<\/svg><\/p>\n<\/div>\n<\/div>\n<\/div>\n<p>\u0627\u06af\u0631 \u0645\u0647\u0627\u062c\u0645 \u0627\u0631\u0633\u0627\u0644 \u06a9\u0646\u062f <code>id=1 OR 1=1<\/code>\u060c \u067e\u0631\u0633 \u0648 \u062c\u0648 \u0645\u06cc \u0634\u0648\u062f:<\/p>\n<div class=\"highlight js-code-highlight\">\n<pre class=\"highlight sql\"><code><span class=\"k\">SELECT<\/span> <span class=\"o\">*<\/span> <span class=\"k\">FROM<\/span> <span class=\"n\">users<\/span> <span class=\"k\">WHERE<\/span> <span class=\"n\">id<\/span> <span class=\"o\">=<\/span> <span class=\"mi\">1<\/span> <span class=\"k\">OR<\/span> <span class=\"mi\">1<\/span><span class=\"o\">=<\/span><span class=\"mi\">1<\/span><span class=\"p\">;<\/span>\n<\/code><\/pre>\n<div class=\"highlight__panel js-actions-panel\">\n<div class=\"highlight__panel-action js-fullscreen-code-action\">\n    <svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"20px\" height=\"20px\" viewbox=\"0 0 24 24\" class=\"highlight-action crayons-icon highlight-action--fullscreen-on\"><title>\u0648\u0627\u0631\u062f \u062d\u0627\u0644\u062a \u062a\u0645\u0627\u0645 \u0635\u0641\u062d\u0647 \u0634\u0648\u06cc\u062f<\/title>\n    <path d=\"M16 3h6v6h-2V5h-4V3zM2 3h6v2H4v4H2V3zm18 16v-4h2v6h-6v-2h4zM4 19h4v2H2v-6h2v4z\"\/>\n<\/svg><\/p>\n<p>    <svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"20px\" height=\"20px\" viewbox=\"0 0 24 24\" class=\"highlight-action crayons-icon highlight-action--fullscreen-off\"><title>\u0627\u0632 \u062d\u0627\u0644\u062a \u062a\u0645\u0627\u0645 \u0635\u0641\u062d\u0647 \u062e\u0627\u0631\u062c \u0634\u0648\u06cc\u062f<\/title>\n    <path d=\"M18 7h4v2h-6V3h2v4zM8 9H2V7h4V3h2v6zm10 8v4h-2v-6h6v2h-4zM8 15v6H6v-4H2v-2h6z\"\/>\n<\/svg><\/p>\n<\/div>\n<\/div>\n<\/div>\n<p>\u0627\u06cc\u0646 \u067e\u0631\u0633 \u0648 \u062c\u0648 \u0647\u0645\u0647 \u0631\u062f\u06cc\u0641 \u0647\u0627 \u0631\u0627 \u0628\u0627\u0632\u06cc\u0627\u0628\u06cc \u0645\u06cc \u06a9\u0646\u062f \u0648 \u062f\u0627\u062f\u0647 \u0647\u0627\u06cc \u062d\u0633\u0627\u0633 \u0631\u0627 \u062f\u0631 \u0645\u0639\u0631\u0636 \u0646\u0645\u0627\u06cc\u0634 \u0642\u0631\u0627\u0631 \u0645\u06cc \u062f\u0647\u062f.  <\/p>\n<h3><span class=\"ez-toc-section\" id=\"%D8%AC%D9%84%D9%88%DA%AF%DB%8C%D8%B1%DB%8C_%D8%A7%D8%B2_%D8%AA%D8%B2%D8%B1%DB%8C%D9%82_SQL_%D8%AF%D8%B1_API_%D9%87%D8%A7%DB%8C_RESTful\"><\/span>\n<p>  \u062c\u0644\u0648\u06af\u06cc\u0631\u06cc \u0627\u0632 \u062a\u0632\u0631\u06cc\u0642 SQL \u062f\u0631 API \u0647\u0627\u06cc RESTful<br \/>\n<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p><strong>1. \u0627\u0632 \u067e\u0631\u0633 \u0648 \u062c\u0648\u0647\u0627\u06cc \u067e\u0627\u0631\u0627\u0645\u062a\u0631\u06cc \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u06a9\u0646\u06cc\u062f<\/strong><\/p>\n<p>\u067e\u0631\u0633 \u0648 \u062c\u0648\u0647\u0627\u06cc \u067e\u0627\u0631\u0627\u0645\u062a\u0631\u06cc \u062a\u0636\u0645\u06cc\u0646 \u0645\u06cc \u06a9\u0646\u0646\u062f \u06a9\u0647 \u0648\u0631\u0648\u062f\u06cc \u0628\u0647 \u0639\u0646\u0648\u0627\u0646 \u062f\u0627\u062f\u0647 \u062f\u0631 \u0646\u0638\u0631 \u06af\u0631\u0641\u062a\u0647 \u0645\u06cc \u0634\u0648\u062f\u060c \u0646\u0647 \u06a9\u062f \u0627\u062c\u0631\u0627\u06cc\u06cc. \u062f\u0631 \u0627\u06cc\u0646\u062c\u0627 \u06cc\u06a9 \u0646\u0633\u062e\u0647 \u0627\u0645\u0646 \u062a\u0631 \u0627\u0632 \u06a9\u062f \u0628\u0627\u0644\u0627 \u0622\u0645\u062f\u0647 \u0627\u0633\u062a:<\/p>\n<div class=\"highlight js-code-highlight\">\n<pre class=\"highlight python\"><code><span class=\"nd\">@app.route<\/span><span class=\"p\">(<\/span><span class=\"sh\">'<\/span><span class=\"s\">\/users<\/span><span class=\"sh\">'<\/span><span class=\"p\">,<\/span> <span class=\"n\">methods<\/span><span class=\"o\">=<\/span><span class=\"p\">[<\/span><span class=\"sh\">'<\/span><span class=\"s\">GET<\/span><span class=\"sh\">'<\/span><span class=\"p\">])<\/span>\n<span class=\"k\">def<\/span> <span class=\"nf\">get_user<\/span><span class=\"p\">():<\/span>\n    <span class=\"n\">user_id<\/span> <span class=\"o\">=<\/span> <span class=\"n\">request<\/span><span class=\"p\">.<\/span><span class=\"n\">args<\/span><span class=\"p\">.<\/span><span class=\"nf\">get<\/span><span class=\"p\">(<\/span><span class=\"sh\">'<\/span><span class=\"s\">id<\/span><span class=\"sh\">'<\/span><span class=\"p\">)<\/span>\n    <span class=\"n\">conn<\/span> <span class=\"o\">=<\/span> <span class=\"n\">sqlite3<\/span><span class=\"p\">.<\/span><span class=\"nf\">connect<\/span><span class=\"p\">(<\/span><span class=\"sh\">'<\/span><span class=\"s\">database.db<\/span><span class=\"sh\">'<\/span><span class=\"p\">)<\/span>\n    <span class=\"n\">cursor<\/span> <span class=\"o\">=<\/span> <span class=\"n\">conn<\/span><span class=\"p\">.<\/span><span class=\"nf\">cursor<\/span><span class=\"p\">()<\/span>\n    <span class=\"n\">query<\/span> <span class=\"o\">=<\/span> <span class=\"sh\">\"<\/span><span class=\"s\">SELECT * FROM users WHERE id = ?;<\/span><span class=\"sh\">\"<\/span>\n    <span class=\"n\">cursor<\/span><span class=\"p\">.<\/span><span class=\"nf\">execute<\/span><span class=\"p\">(<\/span><span class=\"n\">query<\/span><span class=\"p\">,<\/span> <span class=\"p\">(<\/span><span class=\"n\">user_id<\/span><span class=\"p\">,))<\/span>\n    <span class=\"n\">user<\/span> <span class=\"o\">=<\/span> <span class=\"n\">cursor<\/span><span class=\"p\">.<\/span><span class=\"nf\">fetchone<\/span><span class=\"p\">()<\/span>\n    <span class=\"k\">return<\/span> <span class=\"p\">{<\/span><span class=\"sh\">'<\/span><span class=\"s\">user<\/span><span class=\"sh\">'<\/span><span class=\"p\">:<\/span> <span class=\"n\">user<\/span><span class=\"p\">}<\/span>\n<\/code><\/pre>\n<div class=\"highlight__panel js-actions-panel\">\n<div class=\"highlight__panel-action js-fullscreen-code-action\">\n    <svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"20px\" height=\"20px\" viewbox=\"0 0 24 24\" class=\"highlight-action crayons-icon highlight-action--fullscreen-on\"><title>\u0648\u0627\u0631\u062f \u062d\u0627\u0644\u062a \u062a\u0645\u0627\u0645 \u0635\u0641\u062d\u0647 \u0634\u0648\u06cc\u062f<\/title>\n    <path d=\"M16 3h6v6h-2V5h-4V3zM2 3h6v2H4v4H2V3zm18 16v-4h2v6h-6v-2h4zM4 19h4v2H2v-6h2v4z\"\/>\n<\/svg><\/p>\n<p>    <svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"20px\" height=\"20px\" viewbox=\"0 0 24 24\" class=\"highlight-action crayons-icon highlight-action--fullscreen-off\"><title>\u0627\u0632 \u062d\u0627\u0644\u062a \u062a\u0645\u0627\u0645 \u0635\u0641\u062d\u0647 \u062e\u0627\u0631\u062c \u0634\u0648\u06cc\u062f<\/title>\n    <path d=\"M18 7h4v2h-6V3h2v4zM8 9H2V7h4V3h2v6zm10 8v4h-2v-6h6v2h-4zM8 15v6H6v-4H2v-2h6z\"\/>\n<\/svg><\/p>\n<\/div>\n<\/div>\n<\/div>\n<p><strong>2. \u0627\u0639\u062a\u0628\u0627\u0631 \u0648\u0631\u0648\u062f\u06cc \u06a9\u0627\u0631\u0628\u0631<\/strong><\/p>\n<p>\u0647\u0645\u06cc\u0634\u0647 \u0648\u0631\u0648\u062f\u06cc \u0631\u0627 \u0628\u0631\u0627\u06cc \u0645\u0637\u0627\u0628\u0642\u062a \u0628\u0627 \u0642\u0627\u0644\u0628\u200c\u0647\u0627\u06cc \u0645\u0648\u0631\u062f \u0627\u0646\u062a\u0638\u0627\u0631 \u062a\u0623\u06cc\u06cc\u062f \u06a9\u0646\u06cc\u062f. \u0628\u0647 \u0639\u0646\u0648\u0627\u0646 \u0645\u062b\u0627\u0644:<\/p>\n<div class=\"highlight js-code-highlight\">\n<pre class=\"highlight python\"><code><span class=\"k\">def<\/span> <span class=\"nf\">validate_id<\/span><span class=\"p\">(<\/span><span class=\"n\">user_id<\/span><span class=\"p\">):<\/span>\n    <span class=\"k\">if<\/span> <span class=\"ow\">not<\/span> <span class=\"n\">user_id<\/span><span class=\"p\">.<\/span><span class=\"nf\">isdigit<\/span><span class=\"p\">():<\/span>\n        <span class=\"k\">raise<\/span> <span class=\"nc\">ValueError<\/span><span class=\"p\">(<\/span><span class=\"sh\">\"<\/span><span class=\"s\">Invalid user ID<\/span><span class=\"sh\">\"<\/span><span class=\"p\">)<\/span>\n<\/code><\/pre>\n<div class=\"highlight__panel js-actions-panel\">\n<div class=\"highlight__panel-action js-fullscreen-code-action\">\n    <svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"20px\" height=\"20px\" viewbox=\"0 0 24 24\" class=\"highlight-action crayons-icon highlight-action--fullscreen-on\"><title>\u0648\u0627\u0631\u062f \u062d\u0627\u0644\u062a \u062a\u0645\u0627\u0645 \u0635\u0641\u062d\u0647 \u0634\u0648\u06cc\u062f<\/title>\n    <path d=\"M16 3h6v6h-2V5h-4V3zM2 3h6v2H4v4H2V3zm18 16v-4h2v6h-6v-2h4zM4 19h4v2H2v-6h2v4z\"\/>\n<\/svg><\/p>\n<p>    <svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"20px\" height=\"20px\" viewbox=\"0 0 24 24\" class=\"highlight-action crayons-icon highlight-action--fullscreen-off\"><title>\u0627\u0632 \u062d\u0627\u0644\u062a \u062a\u0645\u0627\u0645 \u0635\u0641\u062d\u0647 \u062e\u0627\u0631\u062c \u0634\u0648\u06cc\u062f<\/title>\n    <path d=\"M18 7h4v2h-6V3h2v4zM8 9H2V7h4V3h2v6zm10 8v4h-2v-6h6v2h-4zM8 15v6H6v-4H2v-2h6z\"\/>\n<\/svg><\/p>\n<\/div>\n<\/div>\n<\/div>\n<p><strong>3. \u0628\u0647\u062a\u0631\u06cc\u0646 \u0631\u0648\u0634 \u0647\u0627\u06cc \u0627\u0645\u0646\u06cc\u062a\u06cc API \u0631\u0627 \u067e\u06cc\u0627\u062f\u0647 \u0633\u0627\u0632\u06cc \u06a9\u0646\u06cc\u062f<\/strong>  <\/p>\n<ul>\n<li>\n<strong>\u0645\u062d\u062f\u0648\u062f \u06a9\u0631\u062f\u0646 \u062f\u0627\u062f\u0647 \u0647\u0627\u06cc \u062f\u0631 \u0645\u0639\u0631\u0636:<\/strong> \u0627\u0632 \u0628\u0627\u0632\u06af\u0631\u062f\u0627\u0646\u062f\u0646 \u06a9\u0644 \u0648\u0631\u0648\u062f\u06cc \u0647\u0627\u06cc \u067e\u0627\u06cc\u06af\u0627\u0647 \u062f\u0627\u062f\u0647 \u062e\u0648\u062f\u062f\u0627\u0631\u06cc \u06a9\u0646\u06cc\u062f.\n<\/li>\n<li>\n<strong>\u0627\u0632 \u0647\u062f\u0631\u0647\u0627\u06cc \u0627\u0645\u0646\u06cc\u062a\u06cc \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u06a9\u0646\u06cc\u062f:<\/strong> \u067e\u06cc\u0627\u062f\u0647 \u0633\u0627\u0632\u06cc \u0647\u062f\u0631 \u0645\u0627\u0646\u0646\u062f <code>Content-Security-Policy<\/code>.\n<\/li>\n<li>\n<strong>\u0641\u0639\u0627\u0644 \u06a9\u0631\u062f\u0646 \u06af\u0632\u0627\u0631\u0634 API:<\/strong> \u0646\u0638\u0627\u0631\u062a \u0628\u0631 \u062f\u0631\u062e\u0648\u0627\u0633\u062a \u0647\u0627 \u0628\u0631\u0627\u06cc \u062a\u0634\u062e\u06cc\u0635 \u0627\u0644\u06af\u0648\u0647\u0627\u06cc \u063a\u06cc\u0631\u0639\u0627\u062f\u06cc.\n<\/li>\n<\/ul>\n<h3><span class=\"ez-toc-section\" id=\"%D8%A7%D8%B2_%D8%AC%D8%B3%D8%AA%D8%AC%D9%88%DA%AF%D8%B1_%D8%A7%D9%85%D9%86%DB%8C%D8%AA_%D9%88%D8%A8_%D8%B3%D8%A7%DB%8C%D8%AA_%D8%B1%D8%A7%DB%8C%DA%AF%D8%A7%D9%86_%D8%A8%D8%B1%D8%A7%DB%8C_%D9%85%D8%AD%D8%A7%D9%81%D8%B8%D8%AA_%D8%A7%D8%B2_SQLi_%D8%A7%D8%B3%D8%AA%D9%81%D8%A7%D8%AF%D9%87_%DA%A9%D9%86%DB%8C%D8%AF\"><\/span>\n<p>  \u0627\u0632 \u062c\u0633\u062a\u062c\u0648\u06af\u0631 \u0627\u0645\u0646\u06cc\u062a \u0648\u0628 \u0633\u0627\u06cc\u062a \u0631\u0627\u06cc\u06af\u0627\u0646 \u0628\u0631\u0627\u06cc \u0645\u062d\u0627\u0641\u0638\u062a \u0627\u0632 SQLi \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u06a9\u0646\u06cc\u062f<br \/>\n<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>\u0627\u0628\u0632\u0627\u0631 \u0628\u0631\u0631\u0633\u06cc \u0627\u0645\u0646\u06cc\u062a \u0648\u0628 \u0633\u0627\u06cc\u062a \u0645\u0627 \u0634\u0646\u0627\u0633\u0627\u06cc\u06cc \u0622\u0633\u06cc\u0628 \u067e\u0630\u06cc\u0631\u06cc \u0647\u0627\u06cc \u062a\u0632\u0631\u06cc\u0642 SQL \u0631\u0627 \u0633\u0627\u062f\u0647 \u0645\u06cc \u06a9\u0646\u062f. \u062f\u0631 \u0632\u06cc\u0631 \u0646\u0645\u0648\u0646\u0647 \u0627\u06cc \u0627\u0632 \u0627\u0633\u06a9\u0631\u06cc\u0646 \u0634\u0627\u062a \u06af\u0632\u0627\u0631\u0634 \u0627\u0632 \u0627\u0628\u0632\u0627\u0631 \u0645\u0627 \u0628\u0631\u0627\u06cc \u06a9\u0645\u06a9 \u0628\u0647 \u062a\u062c\u0633\u0645 \u06cc\u0627\u0641\u062a\u0647 \u0647\u0627\u06cc \u0622\u0646 \u0622\u0648\u0631\u062f\u0647 \u0634\u062f\u0647 \u0627\u0633\u062a:  <\/p>\n<p> <\/p>\n<p>\u0627\u0632 \u0627\u06cc\u0646 \u0627\u0628\u0632\u0627\u0631 \u0628\u0631\u0627\u06cc \u0627\u0633\u06a9\u0646 \u0646\u0642\u0627\u0637 \u067e\u0627\u06cc\u0627\u0646\u06cc RESTful API \u0648 \u0627\u06cc\u0645\u0646 \u0633\u0627\u0632\u06cc \u0628\u0631\u0646\u0627\u0645\u0647 \u062e\u0648\u062f \u0642\u0628\u0644 \u0627\u0632 \u0633\u0648\u0621 \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0645\u0647\u0627\u062c\u0645\u0627\u0646 \u0627\u0632 \u0647\u0631\u06af\u0648\u0646\u0647 \u062d\u0641\u0631\u0647 \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u06a9\u0646\u06cc\u062f.  <\/p>\n<p>\u0639\u0644\u0627\u0648\u0647 \u0628\u0631 \u0627\u06cc\u0646\u060c \u062f\u0631 \u0627\u06cc\u0646\u062c\u0627 \u06cc\u06a9 \u0639\u06a9\u0633 \u0641\u0648\u0631\u06cc \u0627\u0632 \u0635\u0641\u062d\u0647 \u0627\u0635\u0644\u06cc \u0627\u0628\u0632\u0627\u0631 \u0645\u0627 \u0628\u0631\u0627\u06cc \u0646\u0634\u0627\u0646 \u062f\u0627\u062f\u0646 \u0633\u0647\u0648\u0644\u062a \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0627\u0632 \u0622\u0646 \u0622\u0648\u0631\u062f\u0647 \u0634\u062f\u0647 \u0627\u0633\u062a:  <\/p>\n<p><img decoding=\"async\" src=\"https:\/\/media2.dev.to\/dynamic\/image\/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto\/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fzvgwbn84w4x10mkcgdnh.jpeg\" alt=\"\u062a\u0635\u0648\u06cc\u0631 \u0635\u0641\u062d\u0647 \u0648\u0628 \u0627\u0628\u0632\u0627\u0631 \u0631\u0627\u06cc\u06af\u0627\u0646 \u06a9\u0647 \u062f\u0631 \u0622\u0646 \u0645\u06cc \u062a\u0648\u0627\u0646\u06cc\u062f \u0628\u0647 \u0627\u0628\u0632\u0627\u0631\u0647\u0627\u06cc \u0627\u0631\u0632\u06cc\u0627\u0628\u06cc \u0627\u0645\u0646\u06cc\u062a\u06cc \u0628\u0631\u0627\u06cc \u062a\u0634\u062e\u06cc\u0635 SQLi \u062f\u0633\u062a\u0631\u0633\u06cc \u062f\u0627\u0634\u062a\u0647 \u0628\u0627\u0634\u06cc\u062f\" loading=\"lazy\" width=\"800\" height=\"393\" title=\"\"><\/p>\n<h3><span class=\"ez-toc-section\" id=\"%DA%86%D8%B1%D8%A7_%D8%B1%D9%88%DB%8C_%D9%BE%DB%8C%D8%B4%DA%AF%DB%8C%D8%B1%DB%8C_%D8%A7%D8%B2_SQLi_%D8%AF%D8%B1_API%D9%87%D8%A7_%D8%AA%D9%85%D8%B1%DA%A9%D8%B2_%DA%A9%D9%86%DB%8C%D9%85%D8%9F\"><\/span>\n<p>  \u0686\u0631\u0627 \u0631\u0648\u06cc \u067e\u06cc\u0634\u06af\u06cc\u0631\u06cc \u0627\u0632 SQLi \u062f\u0631 API\u0647\u0627 \u062a\u0645\u0631\u06a9\u0632 \u06a9\u0646\u06cc\u0645\u061f<br \/>\n<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<ol>\n<li>\n<strong>\u0631\u0634\u062f \u06cc\u06a9\u067e\u0627\u0631\u0686\u0647 \u0633\u0627\u0632\u06cc API:<\/strong> API \u0647\u0627 \u0627\u063a\u0644\u0628 \u062f\u0627\u062f\u0647 \u0647\u0627\u06cc \u062d\u0633\u0627\u0633 \u0631\u0627 \u0645\u062f\u06cc\u0631\u06cc\u062a \u0645\u06cc \u06a9\u0646\u0646\u062f \u0648 \u0622\u0646\u0647\u0627 \u0631\u0627 \u0628\u0647 \u0627\u0647\u062f\u0627\u0641 \u062c\u0630\u0627\u0628\u06cc \u062a\u0628\u062f\u06cc\u0644 \u0645\u06cc \u06a9\u0646\u0646\u062f.\n<\/li>\n<li>\n<strong>\u0634\u062f\u062a \u0628\u0627\u0644\u0627:<\/strong> \u062d\u0645\u0644\u0627\u062a SQLi \u0645\u06cc \u062a\u0648\u0627\u0646\u062f \u0645\u0646\u062c\u0631 \u0628\u0647 \u0646\u0642\u0636 \u062f\u0627\u062f\u0647 \u0647\u0627 \u0648 \u0636\u0631\u0631\u0647\u0627\u06cc \u0645\u0627\u0644\u06cc \u0634\u0648\u062f.\n<\/li>\n<li>\n<strong>\u0646\u06cc\u0627\u0632\u0647\u0627\u06cc \u0627\u0646\u0637\u0628\u0627\u0642:<\/strong> \u0627\u0633\u062a\u0627\u0646\u062f\u0627\u0631\u062f\u0647\u0627\u06cc\u06cc \u0645\u0627\u0646\u0646\u062f OWASP \u0648 PCI DSS \u062f\u0641\u0627\u0639 \u0642\u0648\u06cc SQLi \u0631\u0627 \u0627\u0644\u0632\u0627\u0645\u06cc \u0645\u06cc \u06a9\u0646\u0646\u062f.\n<\/li>\n<\/ol>\n<h3><span class=\"ez-toc-section\" id=\"%D8%A7%D9%81%DA%A9%D8%A7%D8%B1_%D9%86%D9%87%D8%A7%DB%8C%DB%8C\"><\/span>\n<p>  \u0627\u0641\u06a9\u0627\u0631 \u0646\u0647\u0627\u06cc\u06cc<br \/>\n<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>\u062c\u0644\u0648\u06af\u06cc\u0631\u06cc \u0627\u0632 \u062a\u0632\u0631\u06cc\u0642 SQL \u062f\u0631 API \u0647\u0627\u06cc RESTful \u0628\u0647 \u0627\u0642\u062f\u0627\u0645\u0627\u062a \u067e\u06cc\u0634\u06af\u06cc\u0631\u0627\u0646\u0647 \u0646\u06cc\u0627\u0632 \u062f\u0627\u0631\u062f\u060c \u0627\u0632 \u0645\u062f\u06cc\u0631\u06cc\u062a \u0635\u062d\u06cc\u062d \u0648\u0631\u0648\u062f\u06cc \u062a\u0627 \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0627\u0632 \u0627\u0628\u0632\u0627\u0631\u0647\u0627\u06cc \u0627\u0645\u0646\u06cc\u062a\u06cc. \u0628\u0627 \u062a\u062c\u0632\u06cc\u0647 \u0648 \u062a\u062d\u0644\u06cc\u0644 API \u0647\u0627\u06cc \u062e\u0648\u062f \u0628\u0627 \u0645\u0627 \u0634\u0631\u0648\u0639 \u06a9\u0646\u06cc\u062f <strong>\u0627\u0628\u0632\u0627\u0631 \u0628\u0631\u0631\u0633\u06cc \u0627\u0645\u0646\u06cc\u062a \u0648\u0628 \u0633\u0627\u06cc\u062a<\/strong> \u0628\u0631\u0627\u06cc \u0627\u0631\u0632\u06cc\u0627\u0628\u06cc \u0622\u0633\u06cc\u0628\u200c\u067e\u0630\u06cc\u0631\u06cc \u0631\u0627\u06cc\u06af\u0627\u0646  <\/p>\n<p>\u0627\u0632 \u0628\u0631\u0646\u0627\u0645\u0647 \u0647\u0627\u06cc \u062e\u0648\u062f \u0645\u062d\u0627\u0641\u0638\u062a \u06a9\u0646\u06cc\u062f\u060c \u0627\u0632 \u062f\u0627\u062f\u0647 \u0647\u0627\u06cc \u062d\u0633\u0627\u0633 \u0645\u062d\u0627\u0641\u0638\u062a \u06a9\u0646\u06cc\u062f \u0648 \u0627\u0645\u0646\u06cc\u062a API \u0631\u0627 \u0627\u0645\u0631\u0648\u0632 \u0627\u0641\u0632\u0627\u06cc\u0634 \u062f\u0647\u06cc\u062f!  <\/p>\n<\/p><\/div>\n","protected":false},"excerpt":{"rendered":"<p>Summarize this content to 400 words in Persian Lang \u062f\u0631\u06a9 SQL Injection (SQLi) \u062f\u0631 RESTful API SQL Injection (SQLi) \u06cc\u06a9\u06cc \u0627\u0632 \u0631\u0627\u06cc\u062c\u200c\u062a\u0631\u06cc\u0646 \u0622\u0633\u06cc\u0628\u200c\u067e\u0630\u06cc\u0631\u06cc\u200c\u0647\u0627 \u062f\u0631 \u0628\u0631\u0646\u0627\u0645\u0647\u200c\u0647\u0627\u06cc \u06a9\u0627\u0631\u0628\u0631\u062f\u06cc \u0648\u0628 \u0627\u0633\u062a \u06a9\u0647 API\u0647\u0627\u06cc RESTful \u0631\u0627 \u0628\u0631\u0627\u06cc \u0627\u0633\u062a\u062e\u0631\u0627\u062c \u0627\u0637\u0644\u0627\u0639\u0627\u062a \u062d\u0633\u0627\u0633 \u06cc\u0627 \u0628\u0647 \u062e\u0637\u0631 \u0627\u0646\u062f\u0627\u062e\u062a\u0646 \u0633\u06cc\u0633\u062a\u0645\u200c\u0647\u0627 \u0647\u062f\u0641 \u0642\u0631\u0627\u0631 \u0645\u06cc\u200c\u062f\u0647\u062f. API\u0647\u0627\u06cc REST \u06a9\u0647 \u0628\u0631 \u0645\u062f\u06cc\u0631\u06cc\u062a \u0646\u0627\u062f\u0631\u0633\u062a \u0648\u0631\u0648\u062f\u06cc \u06a9\u0627\u0631\u0628\u0631 \u0645\u062a\u06a9\u06cc \u0647\u0633\u062a\u0646\u062f\u060c \u0627\u0647\u062f\u0627\u0641 &hellip;<\/p>\n","protected":false},"author":2,"featured_media":84252,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"","fifu_image_alt":"","footnotes":""},"categories":[339],"tags":[],"class_list":["post-84251","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-dev"],"_links":{"self":[{"href":"https:\/\/nabfollower.com\/blog\/wp-json\/wp\/v2\/posts\/84251","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/nabfollower.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/nabfollower.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/nabfollower.com\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/nabfollower.com\/blog\/wp-json\/wp\/v2\/comments?post=84251"}],"version-history":[{"count":0,"href":"https:\/\/nabfollower.com\/blog\/wp-json\/wp\/v2\/posts\/84251\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/nabfollower.com\/blog\/wp-json\/wp\/v2\/media\/84252"}],"wp:attachment":[{"href":"https:\/\/nabfollower.com\/blog\/wp-json\/wp\/v2\/media?parent=84251"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/nabfollower.com\/blog\/wp-json\/wp\/v2\/categories?post=84251"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/nabfollower.com\/blog\/wp-json\/wp\/v2\/tags?post=84251"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}