4 ms·
Insert using SQL parameters is "escaping". The parameterization ensures that the data being passed gets interpreted by the DB as the expected data type by ensur
by InitialBP 5y ago
Insert using SQL parameters is "escaping". The parameterization ensures that the data being passed gets interpreted by the DB as the expected data type by ensuring special characters aren't interpreted as "special" in that context.
- dagss 5y agoI think that is a strange use of the word "escape". You "escape" from something, in this context the query string. If parameters are not passed inside the query string then how can you say they are escaped? At least for the database I am familiar with (mssql), the query string is one parameter in the binary protocol, and then there are the other parameters that are not the query string which are used as arguments. Your usage here is a bit like saying that a standalone PNG file is "escaped" from the HTML document it is referenced from...since it is marked as not being HTML...