Write Transactions Are a Footgun with Rust's SQLx and SQLite
emschwartz.me
emschwartz.me
That's surprising, given that SQLite itself supports binding and sanitizing query parameters via sqlite_bind_*(). Is SQLx just blindly calling sqlite3_exec() instead of doing the prepare→bind→step→finalize sequence itself?
> Note: query parameters are not supported.
> Query parameters require the use of prepared statements which this API does support.
> If you require dynamic input data in your SQL, you can use format!() but be very careful doing this with user input. SQLx does not provide escaping or sanitization for inserting dynamic input into queries this way.
> See query() for details.