Re: PG 9.0 and standard_conforming_strings

Поиск
Список
Период
Сортировка
От David E. Wheeler
Тема Re: PG 9.0 and standard_conforming_strings
Дата
Msg-id E28A3136-41C1-4641-8B0B-1D966E0D4985@kineticode.com
обсуждение исходный текст
Ответ на Re: PG 9.0 and standard_conforming_strings  (Robert Haas <robertmhaas@gmail.com>)
Список pgsql-hackers
On Feb 3, 2010, at 6:16 PM, Robert Haas wrote:

>> Any web framework that interpolates user supplied values into SQL rather
>> than using placeholders is broken from the get go, IMNSHO. I'm not saying
>> that there aren't reasons to hold up moving to SCS, but this isn't one of
>> them.
>
> That seems more than slightly harsh.  I've certainly come across
> situations where interpolating values (with proper quoting of course)
> made more sense than using placeholders.  YMMV, of course.

Not if it leads to Little Bobby Tables's door when, you know, you use SQL conformant strings! Sounds like an app that
needsits quoting function fixed. 

Best,

David



В списке pgsql-hackers по дате отправления:

Предыдущее
От: Michael Meskes
Дата:
Сообщение: Re: NaN/Inf fix for ECPG Re: out-of-scope cursor errors
Следующее
От: Andrew Dunstan
Дата:
Сообщение: Re: PG 9.0 and standard_conforming_strings