5 ms·
What about using prepared statements?
by asabil 10y ago
What about using prepared statements?
- marcloney 10y ago> While JinjaSQL can handle insert/update statements, you are better off using your ORM to handle such statements. JinjaSQL is mostly meant for dynamic select statements that an ORM cannot handle as well. [1] https://github.com/hashedin/jinjasql#when-to-use-jinjasql https://github.com/hashedin/jinjasql#when-to-use-jinjasql
- asabil 10y agoSorry, but this doesn't answer my question. Prepared statements have nothing to do with ORMs.
- jlogsdon 10y agoThis library doesn't run SQL, its only a template engine that gives you back a parameterized query and parameter array back. It's up to you to actually use them with an adapter, which means you can use prepared statements.
- minitech 10y agoWhat about using them? Doesn’t look like this will stop you, if that’s what you mean.
- coderzach 10y agoPrepared statements can't have things like dynamic columns. I.e. imagine the user specifies a list of fields they want to see. Although, in that case you still probably want to lookup that the field exists.
- ksri 10y agoIf you have dynamic table or column names, you can use the |sqlsafe filter. The library will not bind the values in that case, but you've to be sure there's no sql injection in there.
- ksri 10y agoIt doesn't prevent you from using them. You simply get a sql statement with appropriate place holders. You can pass that sql statement to your database library and it will do the right thing - including binding the parameters and creating prepared statements as necessary.