4 ms·
It's a little difficult to parse through the README, but I believe placeholders and placeholder structure is being rendered in the SQL, not placeholder values.
by chrisjc 3y ago
It's a little difficult to parse through the README, but I believe placeholders and placeholder structure is being rendered in the SQL, not placeholder values.
ps = f'SELECT * FROM table WHERE field1 = {q/value1} AND field2 > {q/value2}'
# SELECT * FROM table WHERE field1 = ? AND field2 > ?
However, I would imagine that if any external input is passed through to this framework, then there might still be the possibility of SQL injection attacks passing through this framework and ending up in the prepared statement SQL.