Want everyone on your software team to learn this? Free 14-day trial.

Train my team
The Principle of Least Privilege
Python
# Connect to the database as the read-only user since we are
# not updating any information
connection = psycopg.connect(
               dbname   = "database",
               user     = "readonly",
               password = os.getenv("DB_READONLY_USER_PASSWORD")
             )

with connection:
  with connection.cursor() as cursor:
    cursor.execute("SELECT * FROM users WHERE email = %(email)s", dict(email=email))
    return cursor.fetchone()