This class of sql injection issues can be eliminated by simply enforcing that all queries are string literals.