3 ms·
I couldn't remember, but checked - I am replacing ' with _ in the actual code https://github.com/mapmeld/fortran-machine/blob/master/marsupial.f90#L43 https://g
by mapmeld 7y ago
I couldn't remember, but checked - I am replacing ' with _ in the actual code https://github.com/mapmeld/fortran-machine/blob/master/marsupial.f90#L43 https://github.com/mapmeld/fortran-machine/blob/master/marsu...
- lotyrin 7y agoGenerating an SQL string with any input from the user is not accepted best practice, even if that were a sufficient way to achieve it (I suspect it would disallow a parameter string to contain a legitimate, escaped ' character). Generally, it is recommended that you create a prepared statement entirely from static SQL string(s) (no user input) and then bind parameters into it, such that there is no possibility for any user input to be parsed as SQL: https://www.sqlite.org/c3ref/stmt.html https://www.sqlite.org/c3ref/stmt.html