API proposal: custom interpolated string handler
@mgravell ci sta già lavorando.
Dal 14/12/2024.
Valutazione
Questa issue non è ancora stata valutata.
Descrizione
Right now, the preferred way of passing args to Dapper requires a second parameter, for example:
string name = ...
int id = ...
conn.Execute("""
update customer
set name = @name
where id = @id
""", new { name, id });
This works; Dapper (vanilla) has code to emit custom per-type code to extract the parameters, and DapperAOT has additional code to pre-gen that as AOT and better validation (mismatched args etc). Additional per-value parameter settings are awkward, but overall: it works.
However!
There is also a possibility to use a custom "interpolated string handler". I have a fully working prototype that allows the following:
string name = ...
int id = ...
conn.Execute($"""
update customer
set name = @{name}
where id = @{id}
""");
This is not a string, and is zero alloc, fully parameterized (SQLi safe), etc. Note that the leading @ (or : etc) is primarily because ADO.NET does not directly expose the parameter token of a given connection, but IMO it helps make it very clear what is going on.
Under the hood, this emits fundamentally the same SQL, even using the argument-expression feature to generate sensible parameter names where possible (name and id in this case). Additionally, from .NET 9 the "alt-lookup" feature of dictionaries is used to avoid allocating a new string per usage. There is zero runtime ref-emit etc needed for packing parameters - we basically trick the C# compiler into doing that work for us!
We could also potentially use the optional format parameters to convey other information, for example:l {name:1000} could set the .Size to 1000, and {qty:P=5,S=3} could set the .Precision and .Scale.
Genuine question: is this an improvement? Is this worth adding new overloads of some core methods? Is this technically nice but not worth the mental addition? Or is this hell-yeah-lets-do-this?
Separately, an analyzer in AOT is proposed to spot interpolated string uses that are susceptible to SQLi (i.e. the type is string); I would also propose that we start shipping Dapper.Advisor inside Dapper, to light up all those checks by default.
- Lingua principale
- C#
- Stelle
- 18.4k
- Fork
- 3.7k
- Merge medio
- 2g 5h
- PR unite (30g)
- 4
Preparare l'ambiente
Questo progetto non fornisce container di sviluppo, Dockerfile né guida per i contributori, quindi l'ambiente è a tuo carico: parti dal suo README e consulta la nostra guida al primo contributo per i passaggi generali.
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di DapperLib/Dapper
-
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 68/100
-
Dapper.Rainbow uses DbConnection on Init instead of IDbConnectionForse già presa @Khaos66 l’ha presa 1554 giorni fa. Aperta
Difficoltà 2/5 1-3 ore Idoneità per principianti 68/100
-
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 78/100
-
Dapper.StrongName 2.1.86 fails strong-name signature verification (all TFMs) — works in 2.1.79Aperta
Difficoltà 3/5 1-2 giorni Idoneità per principianti 65/100
-
New Decimal types supportAperta
Difficoltà 5/5 Più di una settimana Idoneità per principianti 30/100
Tutte le issue di DapperLib/Dapper
Issue simili
-
[Doc Gap] Document new --enable-public-network-access breaking change for azurebackup vault createApertacopilot documentation
Difficoltà 2/5 1-3 ore Idoneità per principianti 86/100
I maintainer di solito rispondono entro 1 giorno
-
area-dashboard
Difficoltà 2/5 1-3 ore Idoneità per principianti 68/100
I maintainer di solito rispondono entro 1 giorno
-
0 - Backlog Bug
Difficoltà 2/5 1-3 ore Idoneità per principianti 72/100
BrighterCommand/Brighter#4539 ·
I maintainer di solito rispondono entro 1 giorno
-
area-networking
Difficoltà 2/5 1-3 ore Idoneità per principianti 68/100
dotnet/aspnetcore#69671 · 1 commento ·
I maintainer di solito rispondono entro 1 giorno
-
test
Difficoltà 2/5 1-3 ore Idoneità per principianti 72/100
NethermindEth/nethermind#14274 ·
I maintainer di solito rispondono entro 1 giorno