• If they're allowed to specify the "from <table> join <some other table>" part, then it's not just the lack of a WHERE clause that you need to worry about. I assume they have read-only access so they can't corrupt data, but unrestricted read access is still wrong in many (most) situations.