After reading this great article on handling multi-valued parameters, I learned about the convenient string_split() function.
I would like to use it in a where clause of a parameterized query like this:
WHERE [SomeTable].[SomeColumn] IN (
SELECT TRIM(value)
FROM string_split(@commaSeparatedListOfValues, ',')
)
Where @commaSeparatedListOfValues is a string received from user input and passed as a parameter.
I am wondering if the function is safe against injections. Is it really impossible to escape a string passed this way? What if the user provides a string like (naively)
"firstValue , ');PRINT 'Hello'-- , thirdValue".
Of course it is added as a parameter in the first step and can do no harm, but does this still apply after splitting it?
I know string_split() can only return tables of string types. I find little to no mention of such issues, so I guess it is a non issue?