Re: SQL Server parameter substitution

Frediano Ziglio <[email protected]>
Newsgroups gmane.comp.db.tds.freetds
Message-ID <CAHt6W4dz=Afj5ovb2zXzf+tkbhY0+VO2OJ7JVHaErR41YMAWeA@mail.gmail.com>
2012/2/28 James K. Lowden <[email protected]>:
> On Mon, 27 Feb 2012 15:53:54 -0800
> Mike Sela <[email protected]> wrote:
>
>> by the time it gets to the DB, it looks like this:
>>
>> SELECT * FROM Customers WHERE CustomerId = 572;
>>
>> The actual parameter substitution appears to be occurring in the
>> pymssql layer, but they tell me that that's because of a limitation
>> in FreeTDS, where parameterized SQL is not handled.  Is that true?
>
> ODBC supports parameterized queries.
>
> db-lib supports parameterized queries for stored procedures.
>
> ct-lib supports parameterized queries for TDS 4.2 and 5.0.  The API
> definition requires the library to get the parameter's on-server
> datatype from the server, a feature not available on Microsoft
> servers.
>
> HTH.
>

pymssql use dblib and build strings before sending query. You can use
pyodbc which use correctly parameter bindings.

Regards
  Frediano Ziglio
_______________________________________________
FreeTDS mailing list
[email protected]
http://lists.ibiblio.org/mailman/listinfo/freetds
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.