Avoiding SQL injection in Dynamic Queries (in plpgsql) - Mailing list pgsql-general

From Allan Kamau
Subject Avoiding SQL injection in Dynamic Queries (in plpgsql)
Date
Msg-id ab1ea6541003170112x5699faan2fb525747c089f54@mail.gmail.com
Whole thread Raw
Responses Re: Avoiding SQL injection in Dynamic Queries (in plpgsql)  (Craig Ringer <craig@postnewspapers.com.au>)
Re: Avoiding SQL injection in Dynamic Queries (in plpgsql)  (Pavel Stehule <pavel.stehule@gmail.com>)
List pgsql-general
When writing dynamic commands (those having "EXECUTE 'some SQL
query';), is there a way to prevent interpretation of input parameters
as pieces of SQL commands? Does quote_literal() function implicitly
protect against this unwanted behaviour.

Allan.

pgsql-general by date:

Previous
From: "A. Kretschmer"
Date:
Subject: Re: return row from plpgsql?
Next
From: Craig Ringer
Date:
Subject: Re: Avoiding SQL injection in Dynamic Queries (in plpgsql)