4 ms·
Yes and your example is the hero case because it isn't just sugar. A t-string implementation for SQL will of course escape the values which is a common securit
by jimwhite 1y ago
Yes and your example is the hero case because it isn't just sugar. A t-string implementation for SQL will of course escape the values which is a common security issue.
https://xkcd.com/327/ https://xkcd.com/327/
- hombre_fatal 1y agoNo, a t-string returns a Template which is basically { strings: str[], values: any[] }. So you would write db.execute(template) to turn template t"... where id = {id}" into a parameterized structure like ("... where id = ?", id).