Re: psycopg, datetime timestamps and intervals
Federico Di Gregorio <fog-NGVKUo/i/[email protected]>
| Newsgroups | gmane.comp.python.db.psycopg.devel |
|---|---|
| Organization | initd.org |
| Message-ID | <[email protected]> |
Il giorno sab, 19/04/2008 alle 22.03 -0500, Matthew Dennis ha scritto: > On Sat, Apr 19, 2008 at 7:47 PM, Federico Di Gregorio <fog-NGVKUo/i/[email protected]> > wrote: > Il giorno sab, 19/04/2008 alle 20.09 +0200, Karsten Hilbert ha > scritto: > > On Sat, Apr 19, 2008 at 10:45:11AM +0200, Federico Di > Gregorio wrote: > > > > > This is wrong. psycopg just does variable substitution. > > Unfortunately. Any chance this will change ? > > > Sincerely I don't know. Note that except for prepared > statements there > won't be any real gain because psycopg will need to adapt the > values > anyway. > > Except that the original example would work as it should and you > would avoid a whole class of SQL Injection attacks psycopg is very well defended against SQL injection. It uses the libpq library functions to quote everything that does nor generate itself (so it is at least as safe as libpq). The original example would have worked, yes. federico -- Federico Di Gregorio http://people.initd.org/fog Debian GNU/Linux Developer [email protected] INIT.D Developer fog-NGVKUo/i/[email protected] The reverse side also has a reverse side. -- Japanese proverb _______________________________________________ Psycopg mailing list Psycopg-IAPFreCvJWPBWskQ1e/[email protected] http://lists.initd.org/mailman/listinfo/psycopg
signature.asc
(application/pgp-signature, 189 B)
-----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.6 (GNU/Linux) iD8DBQBICyTvvcCgrgZGjesRAnRkAJ0eeidmvMBBG1eThNFlKX8osw0oBACfQmQr KugS7teo1V/aEF/G3i7aijY= =m320 -----END PGP SIGNATURE-----