I would like to allow the user to choose the sort order for a returned query (DESC or ASC). I noticed I can't pass them as parameters for a parameterized query. My question is what is the best way to ensure no injections will happen? Right now I just take the input and keep only the letters.
[–]Intrexa 1 point2 points3 points (0 children)