Sign Up

Sign Up to our social questions and Answers Engine to ask questions, answer people’s questions, and connect with other people.

Have an account? Sign In

Have an account? Sign In Now

Sign In

Login to our social questions & Answers Engine to ask questions answer people’s questions & connect with other people.

Sign Up Here

Forgot Password?

Don't have account, Sign Up Here

Forgot Password

Lost your password? Please enter your email address. You will receive a link and will create a new password via email.

Have an account? Sign In Now

You must login to ask a question.

Forgot Password?

Need An Account, Sign Up Here

Please briefly explain why you feel this question should be reported.

Please briefly explain why you feel this answer should be reported.

Please briefly explain why you feel this user should be reported.

Sign InSign Up

The Archive Base

The Archive Base Logo The Archive Base Logo

The Archive Base Navigation

  • SEARCH
  • Home
  • About Us
  • Blog
  • Contact Us
Search
Ask A Question

Mobile menu

Close
Ask a Question
  • Home
  • Add group
  • Groups page
  • Feed
  • User Profile
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Buy Points
  • Users
  • Help
  • Buy Theme
  • SEARCH
Home/ Questions/Q 8829849
In Process

The Archive Base Latest Questions

Editorial Team
  • 0
Editorial Team
Asked: June 14, 20262026-06-14T07:55:46+00:00 2026-06-14T07:55:46+00:00

I want to find all widgets with their common or internal names in a

  • 0

I want to find all widgets with their common or internal names in a certain list query_list. I can do

# Consider query_list = ["a","b","c"]
qlist = '(' + query_list.join(",") + ')'
# this makes 
widgets = Widget.find_by_sql("SELECT * FROM widgets 
     WHERE common_name IN #{qlist} OR internal_name IN #{qlist}")

Now I have a few questions:

  1. Is the above find_by_sql safe regarding SQL injection attacks? It seems like one could put in something dangerous in query_list.
    • How about writing .find_by_sql(["SELECT * FROM widgets
      WHERE common_name IN ? OR internal_name IN ?", ["a","b","c"], ["a","b","c"] ])
    • If it isn’t safe, can we make it safe?
  2. I prefer not to write raw sql if I don’t have to. I know we can write AND conditions in find, as in .find(:conditions=>{:internal_name => ['a','b','c'], :common_name => ['a','b','c']}). Can we also write OR conditions using find?
  3. How about using where? How is this different from using find?
  • 1 1 Answer
  • 0 Views
  • 0 Followers
  • 0
Share
  • Facebook
  • Report

Leave an answer
Cancel reply

You must login to add an answer.

Forgot Password?

Need An Account, Sign Up Here

1 Answer

  • Voted
  • Oldest
  • Recent
  • Random
  1. Editorial Team
    Editorial Team
    2026-06-14T07:55:47+00:00Added an answer on June 14, 2026 at 7:55 am

    The version with placeholders is safe against SQL injection, as long as you don’t mind users being able to select arbitrary widgets, which I assume you don’t. Depending on what version of Rails you have, you can avoid writing raw SQL using chaining; see Ruby on Rails 3 howto make ‘OR’ condition.

    Note that your code as is, or with the placeholders, will cause a database error if the list is empty, or is [nil], so it’s best to test that query_list.first is present before making the query.

    • 0
    • Reply
    • Share
      Share
      • Share on Facebook
      • Share on Twitter
      • Share on LinkedIn
      • Share on WhatsApp
      • Report

Sidebar

Related Questions

I want find all Saturdays and Sundays in A given month. How can I
I want to find all the demo words using PHP and regEx. $input ='demo';
I want to find all foreign keys in a table, and for each foreign
I want to find all items in one collection that do not match another
I want to find all stylesheet definitions in a XHTML file with lxml.etree.findall .
I want to find all img tags in a string of text and put
I want to find all files/dirs that are not equal to .git* , so
I want to find all posts that are tagged with tags that are passed
I want to find all strings containing at least 1 Cyrillic character (basically /.*[А-я].*/)
I've got two arrays where I want to find all the elements in Array0

Explore

  • Home
  • Add group
  • Groups page
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Users
  • Help
  • SEARCH

Footer

© 2021 The Archive Base. All Rights Reserved
With Love by The Archive Base

Insert/edit link

Enter the destination URL

Or link to existing content

    No search term specified. Showing recent items. Search or use up and down arrow keys to select an item.