3 ms·
If I understand your code correctly, you are bypassing DBAPI's binding functionality and opening yourself up for SQL injection. QParams = sqlbind.Dialect.s
by chrisjc 3y ago
If I understand your code correctly, you are bypassing DBAPI's binding functionality and opening yourself up for SQL injection.
QParams = sqlbind.Dialect.some_dialect
@QParams
def make_my_query(value1: str, value2: int):
# SELECT * FROM table WHERE field1 = ? AND field2 > ?
return f'SELECT * FROM table WHERE field1 = {value1} AND field2 > {value2}'
data = connection.execute(*make_my_query(foo, bar), [foo, bar])