3 ms·
Looking at the postgres JDBC source, it sanitizes parameters when prepared statements and parameterization is used. Different implementations may do different t
by reeeeaway 3y ago
Looking at the postgres JDBC source, it sanitizes parameters when prepared statements and parameterization is used. Different implementations may do different things here though
- tester756 3y agoCould you describe it conceptually how they do it?
- reeeeaway 3y agoThe method doAppendEscapeLiteral (Line 66) is a good example; https://github.com/pgjdbc/pgjdbc/blob/master/pgjdbc/src/main/java/org/postgresql/core/Utils.java#66 https://github.com/pgjdbc/pgjdbc/blob/master/pgjdbc/src/main... I didn’t take notes all the way down, but at the end of the day this method is invoked when a prepared statements’ parameters are being bound