4 ms·
Very related: http://www.kalzumeus.com/2010/06/17/falsehoods-programmers-believe-about-names/ http://www.kalzumeus.com/2010/06/17/falsehoods-programmers-b...
by stepvhen 10y ago
Very related: http://www.kalzumeus.com/2010/06/17/falsehoods-programmers-believe-about-names/ http://www.kalzumeus.com/2010/06/17/falsehoods-programmers-b...
- huuu 10y agoI understand what you are saying but this has nothing to do with names but with SQL injections, escaping and prepared statements (the lack of).
- jameshart 10y agoIt has everything to do with names. Among the things that programmers sometimes believe about names, as in this case, is that when you stick apostrophes around them they are always a valid SQL string literal.
- biot 10y agoInexperienced programmers naively believe that about all string input, so the fact they believe it about names isn't particularly interesting.
- Udo 10y agoNo, it's not related. This is about escaping strings in queries, it should not have anything to do with whether programmers thought about all the things that a string can contain or not. User data inside queries absolutely must be escaped at all times, if not that's not a falsehood in belief, it's a bug. Conversely, when a string is properly escaped, you expect the DB not to die on valid input. Which MySQL/MariaDB totally does, by the way, for example when your users submit emojis into the database. Now that would be a falsehood programmers believe about strings, or names if you will.