pub fn sql(input: &str) -> String
Sanitize SQL input (basic - use proper ORM/query builder in production)