Model.find_by_sql(query, binds=[])
http://devdocs.io/rails~4.2/activerecord/querying#method-i-f...
Model.connection.select_all(query, name = nil, binds=[])
http://devdocs.io/rails~4.2/activerecord/connectionadapters/...
Oh, and if you're writing an INSERT statement you have to use connection.execute after all. Have fun!
You just answered your own question. You sanitize the string and then you call connection.execute. Not sure I understand your other issue but it doesn't seem too compelling.
> Not sure I understand your other issue but it doesn't seem too compelling.
If you don't understand the other issue, how do you feel qualified to comment on whether it seems compelling?
Use case: I want to pull up a table of aggregated data for my user. The table is built by joining multiple tables together. The user can dynamically select which columns in the table he wants to see.