Re: Named vs numbered SQL parameters Peter Bex 19 Sep 2019 14:53 UTC
On Thu, Sep 19, 2019 at 05:20:04PM +0300, Lassi Kortela wrote:
> > Here's an ugly but safe option to consider - pass in the query as a list
> > of strings and symbols, where the symbols are to be replaced by
> > appropriate DB-specific magic and the strings stitched together around them:
> >
> > (sql-execute '("INSERT INTO foo VALUES(" myval1 ", " myval2 ")")
> >               '((:myval1 . 1) (:myval2 . 2)))
>
> This may actually be my favorite suggestion so far. The high-level DSL would
> hide all this stuff anyway for most code, so I don't think breaking the SQL
> string into parts like that is too ugly.

I agree it is acceptable.  I'm just slightly worried about for example
being able to store larger queries in separate (non-Scheme) files so
that you can have SQL syntax highlighting and such.  And weird things
like storing the query itself in a database (that's not as weird an idea
as it sounds: Metabase for example does this).

I'll have to think about this...

Cheers,
Peter