2 ms·
No. That's the safe, short answer. Are your customers actually writing SQL for executing against a database or is your app generating SQL? If instead the app
by tom_b 10y ago
No. That's the safe, short answer.
Are your customers actually writing SQL for executing against a database or is your app generating SQL? If instead the app's purpose is to provide a "power interface" to access data (read only?) and generate SQL, there are better choices. Use https query parameters to map to parameterized queries (https://blog.codinghorror.com/give-me-parameterized-sql-or-give-me-death/ https://blog.codinghorror.com/give-me-parameterized-sql-or-g...) which are a much better design choice.