Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

From the mysqljs readme: "Caution This also differs from prepared statements in that all ? are replaced, even those contained in comments and strings."

Eek. "select * from classes where teacher = '?'" -> boom.



Consider applying for YC's Summer 2026 batch! Applications are open till May 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: