Documentation
¶
Overview ¶
Package scriptsql binds a managed script's platform.query parameters into its SQL (#1389): each :name placeholder becomes a SQL literal rendered from the value the script passed, and a registered table's record becomes its quoted name (#1948).
Index ¶
Constants ¶
This section is empty.
Variables ¶
This section is empty.
Functions ¶
func Bind ¶
Bind substitutes :name placeholders in sql with SQL literals rendered from params, and returns the statement to execute.
This exists so a script never has to build SQL by concatenation. An author who writes `"... WHERE region = '" + region + "'"` has written a statement whose meaning depends on the value — the classic mistake, and one an agent authoring under time pressure makes readily. Binding here renders each value according to its own type, with quoting the value cannot escape, so a region named `x' OR '1'='1` is a region name and nothing else.
Substitution is state-aware: a `:name` inside a string literal, inside a quoted identifier, or inside a comment is text, not a placeholder, and `::` is a cast rather than the start of one. Getting that wrong in either direction is a correctness bug (a rewritten literal) or a security bug (an unbound placeholder reaching the engine).
Every placeholder must have a value and every value must be used: an unbound placeholder would reach the query engine as syntax, and an unused value is nearly always a typo in one name or the other.
Types ¶
This section is empty.