The issue with my code is that somebody can put in arbitrary SQL queries within the data field (I think - not sure if it is 100% possible because their data would be enclosed within the programs SQL query, which may break their attempts)
Best way around it is to put in checks to prevent the code from being anything nefarious. I’ll have a think and figure out what’s the best way of doing this, but I assume not constructing the sql strings from scratch but rather using postmodern’s API (postmodern is Common Lisp’s excellent interface to PostgreSQL) makes sense, or the alternate solution recommended in the other reply to your post.