5 ms·
Any string interpolation would open you up to sql injection without a lot of care. It generally recommended to used prepared statements. I guess the q part is
by gpapilion 3y ago
Any string interpolation would open you up to sql injection without a lot of care. It generally recommended to used prepared statements.
I guess the q part is the query parameter for the prepared statement. I’d still be a bit antsy here given the ease of a mistake.
I just don’t get what it’s providing over using my db’s module. Usually the dialect is close but different enough to require changes to queries.