Re: SQL safe input?

Поиск
Список
Период
Сортировка
От Bruno Wolff III
Тема Re: SQL safe input?
Дата
Msg-id 20050827033348.GA12398@wolff.to
обсуждение исходный текст
Ответ на Re: SQL safe input?  (<operationsengineer1@yahoo.com>)
Ответы Re: SQL safe input?  (<operationsengineer1@yahoo.com>)
Список pgsql-novice
On Fri, Aug 26, 2005 at 15:40:02 -0700,
  operationsengineer1@yahoo.com wrote:
> > IMO the best way to do this is to use bind
> > parameters to pass user input
> > to queries. Then you don't need to escape anything.
> > You might still check
> > for very long strings.
>
> this got me thinking...  is this what you are talking
> about (i use ADOdb)?
>
> $db->Execute("INSERT INTO t_customer (customer_name,
> customer_entry_date) VALUES (?,?)",
> array($customer_name, $db->DBDate(time())));
>
> $customer_name is the validated input from the user
> with no escaping of any kind.  is this ok?
>
> this query works just dandy.  does it mean i can start
> sleeping at night?  -lol-

Yes this is the idea. Bad data for the values can't execute unexpected SQL
commands; it can only cause the query to fail.

В списке pgsql-novice по дате отправления:

Предыдущее
От: Bruno Wolff III
Дата:
Сообщение: Re: SQL safe input?
Следующее
От: Alex du Plessis
Дата:
Сообщение: Created objects not visible