4 ms·
Hi, I'm still a little confused about the advantage of prepared statements. No explanation I've seen so far has actually explained why they are good, but my th
by asorbus 17y ago
Hi, I'm still a little confused about the advantage of prepared statements. No explanation I've seen so far has actually explained why they are good, but my thinking was that the developer does not have to remember all of the dangerous characters to escape because the prepared statement stuff do that for you. But now I'm reading here http://dev.mysql.com/tech-resources/articles/4.1/prepared-statements.html http://dev.mysql.com/tech-resources/articles/4.1/prepared-st... that the advantage of paramterization is separating the SQL logic from the data supplied. Why would that matter? You can still supply data such as ' OR 'x'='x
- mildweed 17y agohttp://www.mysqlperformanceblog.com/2006/08/02/mysql-prepared-statements/ http://www.mysqlperformanceblog.com/2006/08/02/mysql-prepare... Pros: 1. Save on query parsing 2. Save on data conversion and copying 3. Avoid SQL Injection 4. Save memory on handling blobs There are also a number of cons. Check out the article before you make this jump.