Is there a way to execute a query with placeholders without preparing the function?

Viewed 81

My codebase has a potential vulnerability of SQL injection that I'd like to secure. I have a few queries in my codebase where I put variables in plain text, like this:

ActiveRecord::Base.connection.execute(
        %{
          SELECT ...
          FROM ...
          JOIN ...
          WHERE ...
           ... model.foreign_id IN (#{array_of_ids})
          GROUP BY 1;
        }
      )

I'm doing it like this because I don't think it's possible to use built-in ActiveRecord queries, due to the complexity of the query (there are ones more complex that we'd like to control).

My first thought was to use exec_query, but I've found I can't use that. I am using pgbouncer in transaction mode, so prepared_statements must remain off. Is there a way to execute a query with placeholders without preparing the function?

1 Answers
Related