Search Postgresql Archives

Re: a stored procedure ..with integer as the parameter

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



surabhi.ahuja wrote:
what do u suggest i do then in that case?
i mean how should i make a query - i mean how do i make a command?

You should always provide well-defined escaping to all data coming from a non-trusted source (i.e. outside your application) and preferably to all data in any case.

If you are using "C" then libpq offers functions to escape strings. Almost all other languages offer something similar.

In general, I never use "raw" functions to build my queries, I have wrapper functions that ensure all queries are well-formed.

What language are you using, and what framework?

--
  Richard Huxton
  Archonet Ltd

---------------------------(end of broadcast)---------------------------
TIP 9: In versions below 8.0, the planner will ignore your desire to
      choose an index scan if your joining column's datatypes do not
      match

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[Index of Archives]     [Postgresql Jobs]     [Postgresql Admin]     [Postgresql Performance]     [Linux Clusters]     [PHP Home]     [PHP on Windows]     [Kernel Newbies]     [PHP Classes]     [PHP Books]     [PHP Databases]     [Postgresql & PHP]     [Yosemite]
  Powered by Linux