3 ms·
There's zero danger of sql injection so long as everything is being passed by parameters. You just concatenate placeholders when you need string concatenation t
by webstrand 1y ago
There's zero danger of sql injection so long as everything is being passed by parameters. You just concatenate placeholders when you need string concatenation to build the query.
- crazygringo 1y agoExactly this. And if you're testing, you've got to test every query combination anyways. It's not just syntax that can be wrong, but logic and performance.