3 ms·
You may have a point for strings. But this is about guarantees for more convoluted expressions in other languages. If you include validating SQL being injection
by BenoitP 3y ago
You may have a point for strings. But this is about guarantees for more convoluted expressions in other languages. If you include validating SQL being injection-free, this is waaay less verbose.
Also this is about enabling a _system_ of templating, and potentially letting the IDE treat it as such and warn you at compile-time. Small snippets tend to creep all over a codebase. Some use-case that this enables:
* HTML templating React-server-side-style: response.send(HTML_PART."""<div>\{name}</div>"""). Here both the HTML is validated, and the variable is escaped; at compile-time. How do you beat this?
* Query-building: businessFilterClause.add(WHERE_VALIDATE."""PRODUCT_MODEL IN \{authorizedModels}"""). And at compile-time or build-time having it validated against a database schema, and the compatibility of your types.