4 ms·
Don't sanitize your inputs; parameterize your queries instead.
by zanecodes 4y ago
Don't sanitize your inputs; parameterize your queries instead.
- Tostino 4y agoI see those as two different solutions to two different, but slightly overlapping problems.
- pessimizer 4y agoGoing to keep those problems a secret?
- Lvl999Noob 4y agoImo, the problems are the same but the conditions are different. If the query is used many times, parameterize it. If the input is used many times, sanitize it. If both are used many times, parameterize.
- robocat 4y agoParameterising works for individual fields in a statement. However for complex queries (the reason for the meta-programmimg comment) you can’t always parameterise the additional subqueries/tables/fields. You can use stored procedures, but that just shifts the necessary code from one language to SQL, and the SQL doesn’t have a robust library you can just use.