4 ms·
Exactly correct - and if you are using Oracle and not using parameterised queries (known as bind variables in the Oracle world), you are quickly going to have p
by fendale 17y ago
Exactly correct - and if you are using Oracle and not using parameterised queries (known as bind variables in the Oracle world), you are quickly going to have performance problems too. That's not the case with MYSQL as it doesn't have a cursor cache in the same way Oracle has. I have no idea about Postgres or SQLServer.
A rule of thumb is that if you are concatenting user input strings into your SQL query strings you are doing it wrong.
- tptacek 17y agoRemember that parameterized queries aren't a panacea. There are plenty of things that don't parameterize well, such as table names, sort orders, and limits.
- deleted 17y ago[deleted]