6 ms·
Parameterized SQL is your friend here.
by skottk 3y ago
Parameterized SQL is your friend here.
- mysterydip 3y agoYeah, that's what's mapped in my head to "sanitizing input" in these cases, as it's the correct way to handle them. I should've unrolled my brain shortcut for the discussion.
- dylan604 3y agoBefore Parameterized SQL was a thing, sanitizing was the thing. There’s a lot of escape_string() type of methods out there.