You don't need to worry about this issue in current development. The general ORM can help you solve it.
If you want to write it by yourself, the parameter value conversion method is generally used to solve the problem. Some class problems rarely occur during development.
However, in some special cases, you must use the SQL spelling method. Therefore, it is inevitable to pay attention to the SQL Injection Protection problem.
The general considerations are as follows:
In SQL, strings, numbers, and dates are commonly used.
For numbers: Check whether the number is correct before splicing. If not, an error is returned.
String: It is okay to replace single quotes with two in SQL. If SQL has the like clause, replace % with \ % and _ \_. Do not replace other characters.
Date type: It can also be processed like the statement type, but an error will be reported during SQL Execution. It is best to judge before merging.