Comment by tcdent
3 months ago
Just keep in mind best practice is to use the built-in parameter interpolation that comes with your db library, since it handles escaping SQL injection for you.
Be very careful if you ever use bare string formatting to construct your queries.
No comments yet
Contribute on Hacker News ↗