http://php.net/manual/en/mysqli.quickstart.prepared-statements.php
http://php.net/manual/en/pdo.prepared-statements.php
prepared queries/statements
embedded parameters
Totally agree.
I would not say "must", because there are cases when it is not possible, or only possible with heavy impact on performance, but i would say you are right with "should"
Are you joking about the difference of "must" and "should" ?!
That is the least important thing you "must" worry about in this codebase!
I cannot believe I'm writing about PDO and prepared queries in 2017!
@gunnicom Prepared statements are essential for
@chris001 I know that they are essential for security. But i also know that you are wrong if you say "they are always faster". They are not. There are some cases where i had significant ( about 50% ) slower queries if using prepared statements. So sometimes they are faster, sometimes they are slower.
@gunnicom
It's easy enough to include a PDO class and implement it into extended code.
We have now set up a new home for suggestions at Trello. All github issues that were labeled 'suggestion' have been moved and will be closed. Certain ones will be progressed within the new Suggestion Box and may be re-opened.
Announcement of moving Suggestions:
https://suitecrm.com/forum/suggestion-box/13691-moving-suggestions-from-github-to
New SuiteCRM Suggestion Box
https://trello.com/b/Ht7LbMqw/suitecrm-suggestion-box
Most helpful comment
@gunnicom