What's wrong with SQL?
It is a bad language.
EDIT: It is completely preposterous that SQL injection is even a thing.
def insert_person(first_name, last_name)
sql.query("insert into persons values(#{first_name}, #{last_name})")
end
So long as you're not plugging form data directly into that function, that works just fine.This is what binding variables is for, but to use them you're either writing for specific platforms (PSQL, Oracle SQL, etc), or you're using middleware that hides the raw SQL from you.