4 ms·
> I'd say about 90% or so of the code I look at where someone is building raw SQL queries has trivial SQL injections in it. Just parameterize the query and you
by Person5478 6y ago
> I'd say about 90% or so of the code I look at where someone is building raw SQL queries has trivial SQL injections in it.
Just parameterize the query and you're done. If someone isn't doing so in 2020 they're either working on a very old system or they're not doing it right.
SQL injection is just not a reason to avoid raw SQL.
One of the reasons I love Dapper.net is because it allows me to use raw SQL and helps solve the only pain point I have with raw SQL, dynamically building queries.