“%s” % format vs “{0}”.format() vs “?” format

余生颓废 提交于 2019-12-17 18:07:17

问题


In this post about SQLite, aaronasterling told me that

  • cmd = "attach \"%s\" as toMerge" % "b.db" : is wrong
  • cmd = 'attach "{0}" as toMerge'.format("b.db") : is correct
  • cmd = "attach ? as toMerge"; cursor.execute(cmd, ('b.db', )) : is right thing

But, I've thought the first and second are the same. What are the differences between those three?


回答1:


"attach \"%s\" as toMerge" % "b.db"

You should use ' instead of ", so you don't have to escape.

You used the old formatting strings that are deprecated.

'attach "{0}" as toMerge'.format("b.db")

This uses the new format string feature from newer Python versions that should be used instead of the old one if possible.

"attach ? as toMerge"; cursor.execute(cmd, ('b.db', ))

This one omits string formatting completely and uses a SQLite feature instead, so this is the right way to do it.

Big advantage: no risk of SQL injection




回答2:


The first and second produce the same result, but the second method is prefered for formatting strings in newer versions of Python.

However the third is the better approach here because it uses parameters instead of manipulating strings. This is both faster and safer.




回答3:


Because it is not being escaped. If you replaced the b.db with user input, it would leave you vulnerable to SQL injection.



来源:https://stackoverflow.com/questions/3691975/s-format-vs-0-format-vs-format

易学教程内所有资源均来自网络或用户发布的内容,如有违反法律规定的内容欢迎反馈
该文章没有解决你所遇到的问题?点击提问,说说你的问题,让更多的人一起探讨吧!