4 ms·
> It’s worse than that: the advice to use parameterized queries goes back to the late 1990s before that legacy software was even started MySQL didn't introduce
by Denvercoder9 6y ago
> It’s worse than that: the advice to use parameterized queries goes back to the late 1990s before that legacy software was even started
MySQL didn't introduce prepared queries until 4.1, which was released in 2004.
- acdha 6y agoYes - this was a common criticism if you were trying to get MySQL into an environment with a different database since this was a SQL92 feature which was good for performance and security. That had often been seen as a performance move or a way to avoid confusing error messages but that started to change by the turn of the century as the technique became more visible and so many web apps were fronting databases rather than static. Poking around https://metacpan.org/pod/DBI https://metacpan.org/pod/DBI I notice support added by some point in 1997, possibly as early as 1996. Python’s DBI spec had it no later than 2001. The other thing to remember is that it wasn’t uncommon to have drivers emulate this behavior on databases which didn’t have protocol level support for it. That didn’t help performance but it did accomplish the goal of making sure that data wasn’t confused with code. To be clear, I’m basing my comments on having used PHP professionally starting with PHP 3 for many projects, including some household name companies. I trained a fair number of people, some of my earliest open source work was in PHP, etc. so I don’t hate the language but I definitely think there are cautionary lessons to learn about the value of defaults and how languages are taught. As we’ve seen with C, telling people to be more diligent is less effective than making the default safe behavior you have to opt out of rather than the reverse.