Slide 27
Slide 27 text
Database library
→ SQLStatement, SQLEscapedString
→ SQLStatement may only be constructed from
programmer-controlled origins
→ Only SQLEscapedString may be combined into
SQLStatement, in predefined safe ways
→ A function accepting Strings and escaping them
for SQL