“%s” % format vs “{0}”.format() vs “?” format

后端 未结 3 694
没有蜡笔的小新
没有蜡笔的小新 2020-12-08 16:42

In this post about SQLite, aaronasterling told me that

  • cmd = \"attach \\\"%s\\\" as toMerge\" % \"b.db\" : is wrong
  • cmd = \'attach
相关标签:
3条回答
  • 2020-12-08 17:07

    Because it is not being escaped. If you replaced the b.db with user input, it would leave you vulnerable to SQL injection.

    0 讨论(0)
  • 2020-12-08 17:12
    "attach \"%s\" as toMerge" % "b.db"
    

    You should use ' instead of ", so you don't have to escape.

    You used the old formatting strings that are deprecated.

    'attach "{0}" as toMerge'.format("b.db")
    

    This uses the new format string feature from newer Python versions that should be used instead of the old one if possible.

    "attach ? as toMerge"; cursor.execute(cmd, ('b.db', ))
    

    This one omits string formatting completely and uses a SQLite feature instead, so this is the right way to do it.

    Big advantage: no risk of SQL injection

    0 讨论(0)
  • 2020-12-08 17:26

    The first and second produce the same result, but the second method is prefered for formatting strings in newer versions of Python.

    However the third is the better approach here because it uses parameters instead of manipulating strings. This is both faster and safer.

    0 讨论(0)
提交回复
热议问题