Re: SQL injection in a ~ or LIKE statement

Поиск
Список
Период
Сортировка
От Harald Armin Massa
Тема Re: SQL injection in a ~ or LIKE statement
Дата
Msg-id 7be3f35d0610222258k54df819r9c47dd9fb4c35267@mail.gmail.com
обсуждение исходный текст
Ответ на Re: SQL injection in a ~ or LIKE statement  ("Uwe C. Schroeder" <uwe@oss4u.com>)
Ответы Re: SQL injection in a ~ or LIKE statement
Список pgsql-general

psycopg2 supports parameters which are escaped properly.

adding: Judging from the mails of  Frederico, developer of psycopg2, he was also in the "early notify circle" of the 8.13->8.14 escaping improvement. So, if done correctly the DB API way, all escaping with psycopg2 is fine.

Harald


--
GHUM Harald Massa
persuadere et programmare
Harald Armin Massa
Reinsburgstraße 202b
70197 Stuttgart
0173/9409607
-
Python: the only language with more web frameworks than keywords.

В списке pgsql-general по дате отправления: