5 ms·
True. Then you could use sql"..." html"..." for each of the given examples and achieve some runtime type safety.
by Timwi 1y ago
True. Then you could use
sql"..."
html"..."
for each of the given examples and achieve some runtime type safety.
- jbverschoor 1y agoAnd you'd end up with almost no improvement. If you pass a "t-string" to a framework, it can force escaping. What you suggest is to rely on escaping by the user (dev), who, if he was aware, would already escape. Unless you'd suggest that it would still return a template, but tagged with a language.
- mcintyre1994 1y agoFWIW the JS equivalent is a template but tagged with a language. It has all the benefits of this template, but IDEs can easily syntax highlight the string. That seems like it would be a bit trickier to do with the Python one which is a shame.
- Timwi 1y agoNo, you misunderstood that completely. They would still be like t-strings, but sql-strings are now a different type from html-strings. The escaping would be done by the library that offers the sql"..." functionality.