Click here to Skip to main content
15,907,149 members

Survey Results

Do you have plans to use the Entity Framework?   [Edit]

Survey period: 10 Nov 2008 to 17 Nov 2008

Having impedance mismatch problems? The Entity Framework could be the solution. Or maybe not. (Suggested by IdeaBlade)

OptionVotes% 
We already use it474.47
Definitely797.52
Maybe27325.98
Probably not17416.56
Definitely not706.66
I don't know what it is35633.87
It's not applicable to my work524.95



 
GeneralRe: How is afraid of the big bad SQL? Pin
PedroMC12-Nov-08 22:56
PedroMC12-Nov-08 22:56 
GeneralRe: How is afraid of the big bad SQL? [modified] Pin
Nemanja Trifunovic13-Nov-08 6:10
Nemanja Trifunovic13-Nov-08 6:10 
GeneralRe: How is afraid of the big bad SQL? Pin
PedroMC13-Nov-08 23:41
PedroMC13-Nov-08 23:41 
GeneralRe: How is afraid of the big bad SQL? Pin
Nemanja Trifunovic14-Nov-08 4:01
Nemanja Trifunovic14-Nov-08 4:01 
GeneralRe: How is afraid of the big bad SQL? Pin
Jeremy Falcon14-Nov-08 8:15
professionalJeremy Falcon14-Nov-08 8:15 
GeneralRe: How is afraid of the big bad SQL? Pin
Nemanja Trifunovic14-Nov-08 8:18
Nemanja Trifunovic14-Nov-08 8:18 
GeneralRe: How is afraid of the big bad SQL? Pin
Jeremy Falcon14-Nov-08 8:23
professionalJeremy Falcon14-Nov-08 8:23 
GeneralRe: How is afraid of the big bad SQL? Pin
PedroMC14-Nov-08 11:35
PedroMC14-Nov-08 11:35 
Nemanja Trifunovic wrote:
And how do you "sanitize" data reliably if it does not pass through the same parser that will ultimatelly proces your SQL query?


Using the facilities provided by the server API and there is nothing special or complex about it. In fact, it amounts to escape a few characters with structural significance for the SQL parser.

Nemanja Trifunovic wrote:
it still requires the discipline on the client programmer's side to sanitize each and every user input and that is simply unrealistic


Unrealistic why?! If a programmer is incapable of validating the data is program will be working on then maybe (s)he should be looking for another occupation.

Any and all data should be validated (at least once). I always validate each and every user, file, network, whatever data input. I always validate each and every data that goes in to a database (using direct SQL, parametrized SQL, API, whatever). I almost always validate (assert) function parameters.

Security is one reason for all this validation but structuring the programs behaviour in my head, reducing bugs and simplifying bug hunting are also strong reasons for it.

Regards.


GeneralRe: How is afraid of the big bad SQL? Pin
Jeremy Falcon14-Nov-08 8:08
professionalJeremy Falcon14-Nov-08 8:08 
GeneralRe: How is afraid of the big bad SQL? Pin
Jeremy Falcon14-Nov-08 8:12
professionalJeremy Falcon14-Nov-08 8:12 
GeneralRe: How is afraid of the big bad SQL? Pin
Nemanja Trifunovic14-Nov-08 9:06
Nemanja Trifunovic14-Nov-08 9:06 
GeneralRe: How is afraid of the big bad SQL? Pin
Jeremy Falcon14-Nov-08 9:48
professionalJeremy Falcon14-Nov-08 9:48 
GeneralRe: How is afraid of the big bad SQL? Pin
Nemanja Trifunovic14-Nov-08 10:15
Nemanja Trifunovic14-Nov-08 10:15 
GeneralRe: How is afraid of the big bad SQL? Pin
Jeremy Falcon14-Nov-08 10:33
professionalJeremy Falcon14-Nov-08 10:33 
GeneralRe: How is afraid of the big bad SQL? Pin
Jeremy Falcon14-Nov-08 8:03
professionalJeremy Falcon14-Nov-08 8:03 
GeneralRe: How is afraid of the big bad SQL? Pin
Nemanja Trifunovic14-Nov-08 8:13
Nemanja Trifunovic14-Nov-08 8:13 
GeneralRe: How is afraid of the big bad SQL? Pin
Jeremy Falcon14-Nov-08 8:22
professionalJeremy Falcon14-Nov-08 8:22 
GeneralRe: How is afraid of the big bad SQL? Pin
Jeremy Falcon11-Nov-08 6:08
professionalJeremy Falcon11-Nov-08 6:08 
GeneralRe: How is afraid of the big bad SQL? Pin
Thomas Weller11-Nov-08 6:56
Thomas Weller11-Nov-08 6:56 
GeneralRe: How is afraid of the big bad SQL? Pin
Jeremy Falcon11-Nov-08 9:47
professionalJeremy Falcon11-Nov-08 9:47 
GeneralRe: How is afraid of the big bad SQL? Pin
Thomas Weller11-Nov-08 22:07
Thomas Weller11-Nov-08 22:07 
GeneralRe: How is afraid of the big bad SQL? Pin
Jeremy Falcon14-Nov-08 8:43
professionalJeremy Falcon14-Nov-08 8:43 
GeneralRe: How is afraid of the big bad SQL? Pin
Thomas Weller16-Nov-08 23:37
Thomas Weller16-Nov-08 23:37 
GeneralRe: How is afraid of the big bad SQL? Pin
Jeremy Falcon17-Nov-08 5:52
professionalJeremy Falcon17-Nov-08 5:52 
GeneralRe: How is afraid of the big bad SQL? Pin
Thomas Weller17-Nov-08 6:03
Thomas Weller17-Nov-08 6:03 

General General    News News    Suggestion Suggestion    Question Question    Bug Bug    Answer Answer    Joke Joke    Praise Praise    Rant Rant    Admin Admin   

Use Ctrl+Left/Right to switch messages, Ctrl+Up/Down to switch threads, Ctrl+Shift+Left/Right to switch pages.