防止SQL注入/好Ruby方法

Zom*_*ies 5 ruby sql-injection

Ruby中防止SQL注入的好方法是什么?

Mik*_*rov 7

直接红宝石?使用预备陈述:

require 'mysql'
db = Mysql.new('localhost', 'user', 'password', 'database')
statement = db.prepare "SELECT * FROM table WHERE field = ?"
statement.execute 'value'
statement.fetch
statement.close
Run Code Online (Sandbox Code Playgroud)