× The internal search function is temporarily non-functional. The current search engine is no longer viable and we are researching alternatives.
As a stop gap measure, we are using Google's custom search engine service.
If you know of an easy to use, open source, search engine ... please contact support@midrange.com.



James wrote:

I also probably need to code the statement in (as you suggest) instead
of passing it.

Yes. Having the statement coded on the i side means the database
optimiser knows about it and can properly optimise performance. Passing
a statement in from the caller means the optimiser has no idea what can
be coming in, and so your performance would probably not be that good.

In addition there is a different problem allowing an SQL statement to be
passed in - SQL injection attacks. Imagine if some naughty person knew
the name of your stored procedure and submitted 'delete * from custmast'
instead of the 'select name from birthdayfile where...'
--buck

As an Amazon Associate we earn from qualifying purchases.

This thread ...


Follow On AppleNews
Return to Archive home page | Return to MIDRANGE.COM home page

This mailing list archive is Copyright 1997-2024 by midrange.com and David Gibbs as a compilation work. Use of the archive is restricted to research of a business or technical nature. Any other uses are prohibited. Full details are available on our policy page. If you have questions about this, please contact [javascript protected email address].

Operating expenses for this site are earned using the Amazon Associate program and Google Adsense.