From: Peter Ertl Date: 2006-06-13T21:27:54+09:00 Subject: Re: ugly ruby code... > > you can store malicious code in an NUMERIC column? NULL, -1, 99999999999999999999999999999, 0 I could imagine all of these could cause trouble depending on db, etc. -------- Original-Nachricht -------- Datum: Tue, 13 Jun 2006 21:20:21 +0900 Von: arnaud stageman An: ruby-talk@ruby-lang.org Betreff: Re: ugly ruby code... > Kroeger, Simon (ext) wrote: > >> > >> Because you avoid sql injection. > > > > From the docs: > > > > "The array form is to be used when the condition input is > > tainted and requires sanitization" > > > > I wouldn't think of an id derived from another table as been tainted. > > Perhaps I'm wrong, but please explain if this is the case. I don't think > > you can store malicious code in an NUMERIC column? > > > > Honestly I don't have any clue about the good and bad method but it > costs nothing to do I believe :) > > >> The first solution is better because you execute only one sql request. > > > > I don't buy that without seen benchmark results. Iterating in pure ruby > > while creating two new arrays (increasing the size each iteration) is > > hardly faster than executing an SQL statement. (those db guys are realy > > speed freaks :)) > > > > Yes you're right. I had not see the problem like that... It would need > further investigations. > As my app will be used in really small production environment, I think > I'll get your solution 'cause I find it more clear! > > > -- > Posted via http://www.ruby-forum.com/.