Re: No parameters support in "create user"?

Поиск
Список
Период
Сортировка
От Gaetano Mendola
Тема Re: No parameters support in "create user"?
Дата
Msg-id 414F7A9E.3020705@bigfoot.com
обсуждение исходный текст
Ответ на Re: No parameters support in "create user"?  (Shachar Shemesh <psql@shemesh.biz>)
Ответы Re: No parameters support in "create user"?  (Shachar Shemesh <psql@shemesh.biz>)
Список pgsql-hackers
Shachar Shemesh wrote:
> Tom Lane wrote:
> 
>> Parameters are only supported in plannable statements
>> (SELECT/INSERT/UPDATE/DELETE; I think there is some hack for DECLARE
>> CURSOR these days too).
>>  
>>
> That's a shame.
> 
> Aside from executing prepared statements, parameters are also useful for 
> preventing SQL injections. Under those cases, they are useful for all 
> commands, not only those that can be prepared.
> 
> Oh well. I'm not sure whether that's extremely clever or downright 
> insane, but I'm solving this problem by calling "Select 
> quote_literal($1)" and "select quote_id($1)", and then using the results.

Create your own plpgsql function and call it.


Regards
Gaetano Mendola




В списке pgsql-hackers по дате отправления:

Предыдущее
От: Gaetano Mendola
Дата:
Сообщение: Re: RSS
Следующее
От: Andrew Sullivan
Дата:
Сообщение: Re: signal 11 on AIX: 7.4.2