Hacker News new | ask | show | jobs
by simonw 952 days ago
Yeah, that's exactly the problem: everything is string interpolation, and no-one has figured out if it's even possible to do the equivalent to prepared statements or escaped strings.