Hello there im trying to run a postgresql query on flask using SQLAlchemy, but I don't understand how I can keep my query sanitized while using the LIKE '%' argument.
db.execute("SELECT * FROM books WHERE isbn LIKE '%:isbn%' OR title LIKE '%:title%L' OR author = '%:author%'", {"isbn": isbn, "title": title, "author": author})
That is what I got but of course it does not run. and I do not want to sacrifice the integrity of the system to be allowed to use LIKE.
Does anyone have a suggestion for me?