且构网

分享程序员开发的那些事...
且构网 - 分享程序员编程开发的那些事

防止python中的SQL注入

更新时间:2023-12-02 09:51:28

来自文档:

con.execute("insert into person(firstname) values (?)", ("Joe",))

这转义了"Joe",所以你想要的是

This escapes "Joe", so what you want is

con.execute("insert into person(firstname) values (?)", (firstname_from_client,))