There are options available as one or more of the above 3 requirements is dropped: http://stackoverflow.com/questions/149380/dynamic-sorting-wi...
There are options available as one or more of the above 3 requirements is dropped: http://stackoverflow.com/questions/149380/dynamic-sorting-wi...
Paging is equally easy, using ROWNUM < X in Oracle or equivalent in other RDBMS.
The order by is a good point. The obvious solution here would be to always have the same sorting as default, and do the user sorting client side (by client here, I mean calling application).
Do you agree that this is a scenario requiring dynamic SQL?
This is somewhat less efficient, but if the alternative is to be open to sqli attacks it'd be my pleasure.
Congratulations, we are no longer relying on bound parameters to prevent SQL injection. THREAD FINISHED! :)
(See another person discussing this here in this thread: http://news.ycombinator.com/item?id=4203929 )