3 ms·
Apparently, people are shocked by the title 'Execute formulas stored in database fields', which they associate with bad experiences involving scripting, SQL gen
by BVegter 3y ago
Apparently, people are shocked by the title 'Execute formulas stored in database fields', which they associate with bad experiences involving scripting, SQL generation, stored procedures, SQL injections, and other vulnerabilities.
However, the point is that the approach presented here is intended to address these vulnerabilities and provide a robust, secure environment.
We are accustomed to applying formulas to entire columns using calculated fields in SQL and have no problem with this; in fact, we gratefully use this option. The approach presented here offers the same safe opportunity but now at a record level. Therefore, there is no scripting, SQL generation, stored procedures, or SQL injection involved. Just as you can safely define a calculated field, you similarly define an expression that returns a value without any possible side effects.
Furthermore, it is not strange to include a formula in a database field. In databases, we register attributes of objects, and sometimes that attribute is an expression, such as the agreed bonus with your employer. Formula fields allow such an attribute to be registered and calculated within SQL. This provides us with a much more flexible, safer, and transparent method than writing a separate program outside the database.