|
|
|
|
|
by EGreg
633 days ago
|
|
Easy. Don’t write queries in a language (SQL) which interpolates content without escaping it for the enclosing structure. Go one level up. For example statements that are prepared should not allow strings in the SQL, but rather variables, and then bind them to values like PDO does |
|
I'd rather have SQL API taking not strings but a special type that string can't be directly converted into without escaping (by default).
In C++ tagged literals could be used to create this special type easily. Similar constructs exist in some other languages