3 ms·
One major problem is that the MySQL "text" protocol doesn't support true parameterised queries. There's no way to pass parameters in the `COM_QUERY` packet: htt
by bgrainger 5y ago
One major problem is that the MySQL "text" protocol doesn't support true parameterised queries. There's no way to pass parameters in the `COM_QUERY` packet: https://dev.mysql.com/doc/internals/en/com-query.html https://dev.mysql.com/doc/internals/en/com-query.html
That's probably why many of the libraries mentioned in this thread use "smoke and mirrors". Of course, it is quite possible to correctly escape a value by rendering it to a string first, _then_ encoding the whole thing.
To have true parameterised queries, you need to use the "binary" protocol, which many MySQL libraries don't offer support for. (MySQL also has some frustrating limitations with the binary protocol, such as not allowing a SQL string containing more than one statement to be prepared.)
- namibj 5y agoPostgreSQL shares that limitation on it's extended query protocol (needed for prepared statements), though you can send multiple queries off before sending the "I'm waiting, hurry up and get back with answers" packet to the server. Not that the native C library (libpq) supports such pipelining...