Skip to main content

query

Function query 

Source
pub fn query(sql: impl SqlSafeStr) -> Query
Expand description

Starts a statement. The SQL is written with ? markers.

Takes sqlx::SqlSafeStr, which is &'static str or an explicit sqlx::AssertSqlSafe — not any String. That is the whole of what stops a column list, a predicate or a value being interpolated into a statement by accident: a literal needs nothing, and a statement built at runtime has to say so at the call site. Every value goes through Query::bind regardless, so a filter is compared and never executed.