Comments (6)
Hi @generik0, thanks for your feedback, could you please show me an example of what you expect ?
from querybuilder.
Her is an example of the translation. _sqlTypeMapper is just a dictionary with e.g. System.Int type = int.
var r = compiler.Compile(query);
var parameters = r.Bindings.Select(parameter =>
{
var para = new StringBuilder();
para.Append($"DECLARE @{parameter.Key} {_sqlTypeMapper[parameter.Value.GetType()]}\n");
para.Append($"SET @{parameter.Key} = {parameter.Value}");
return para.ToString();
});
var sqlFull = {string.Join("\n", parameters)}\n{r.Sql};
from querybuilder.
Ah ok I got your idea now, but why not replacing the values of the parameters inline similar to SqlResult.ToString()
method ?
https://github.com/sqlkata/querybuilder/blob/master/QueryBuilder/SqlResult.cs#L40-L59
from querybuilder.
If we use the parameter query, wont the query still be cached and using the parameters get a performance “boost”? I.e. instead of different versions of the same query.
We will also prevent SQL injections.
Maybe this is to much of a corner case?
We are using DevExtreme dashboards that we feed with custom sql “data sources”. This is why the sql with parameters will benefit us...
from querybuilder.
Converting the bindings to the actual string of the SQL statement opens you back up to SQL injection and i'd advise against doing that at all cost. Also, I'm not a SQL expert but I believe you would most likely loose the cache hit for the query plan under some circumstances / queries if you convert the bindings into the statement as text. It's something to test but i'd still advise against.
I just made a quick glance at some documentation for the DevExpress dashboard. Are you setting the datasource in code?
If so, please refer to this link
You'll notice that the CustomSqlQuery object has a property called 'Parameters' and you would only really need to map the SqlResult.Bindings into that collection.
If the above isn't your use case; please provide us a little more information so we can try to help.
Thanks
from querybuilder.
Sounds like the best plan.....
from querybuilder.
Related Issues (20)
- Oracle connection pooling with SqlKata
- Can you please include https://github.com/sqlkata/querybuilder/commit/f3d7c924f4d11c33056d7b002f9d5066dc856117 & re-publish 2.4.0 ?
- RobiniaDocs API Explorer
- Compile query with parameters for ODBC Connection
- Assigning NULL value to column with AsUpdate throws NotSupportedException HOT 1
- db access where day error No value given for one or more required parameters.
- [SQLServer] insert bool value #437 HOT 1
- Possible documentation error
- Distinct AsCount error
- Vulnerability in System.Text.RegularExpressions 4.3.0
- FromRaw can't translate list type parameter properly HOT 1
- how to use include HOT 2
- Question: Combining multiple Statements HOT 1
- Error on WhereContains HOT 1
- Getting Raw SQL from the package, without passing it to the database engine HOT 5
- Error when trying to insert into Always Encrypted column
- SqlServerCompiler Limit generates different query on compile compared to previous versions HOT 3
- Postgres over-escaping ? HOT 1
- `With` missing if defined in sub query HOT 2
- Use RetryProvider in SqlKata.Execution
Recommend Projects
-
React
A declarative, efficient, and flexible JavaScript library for building user interfaces.
-
Vue.js
🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.
-
Typescript
TypeScript is a superset of JavaScript that compiles to clean JavaScript output.
-
TensorFlow
An Open Source Machine Learning Framework for Everyone
-
Django
The Web framework for perfectionists with deadlines.
-
Laravel
A PHP framework for web artisans
-
D3
Bring data to life with SVG, Canvas and HTML. 📊📈🎉
-
Recommend Topics
-
javascript
JavaScript (JS) is a lightweight interpreted programming language with first-class functions.
-
web
Some thing interesting about web. New door for the world.
-
server
A server is a program made to process requests and deliver data to clients.
-
Machine learning
Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.
-
Visualization
Some thing interesting about visualization, use data art
-
Game
Some thing interesting about game, make everyone happy.
Recommend Org
-
Facebook
We are working to build community through open source technology. NB: members must have two-factor auth.
-
Microsoft
Open source projects and samples from Microsoft.
-
Google
Google ❤️ Open Source for everyone.
-
Alibaba
Alibaba Open Source for everyone
-
D3
Data-Driven Documents codes.
-
Tencent
China tencent open source team.
from querybuilder.