I have an originally SQL query:
f"SELECT FIELDS(ALL) from xxxx WHERE CreatedDate >= {start_time}"
I wanted to make that query safe from sql injection attack but I could not see how can I know that I did it right. This is the new version that should be safe:
f"SELECT FIELDS(ALL) from xxxx WHERE CreatedDate >= %s" % (start_time,)
I'm using it in an API call. The query itself will be excecated in the other side (third party). I want to send the query as parameter in the api call I would like to get some tips regarding this issue Thank you!