docs(10_Wiki): 위키 구조 정리 — 언어 튜토리얼 카테고리 폴더 제거 + 신규 자산 동기화

Topic_CSS/Topic_HTML/Topic_JavaScript/Topic_Prompt/Topic_Comfyui 등 기존 카테고리 폴더를 정리하고,
Topic_Graphic/Dev 등 신규 산출물과 Topics 내부 세션/메모리 기록을 동기화.
This commit is contained in:
Antigravity Agent
2026-07-05 00:10:59 +09:00
parent a397bc4720
commit 1cfd3bbb56
1495 changed files with 68534 additions and 27 deletions
@@ -0,0 +1,70 @@
---
id: python-mysql-where
title: "Python MySQL Where"
category: "Programming_Language"
status: "draft"
verification_status: "conceptual"
canonical_id: ""
aliases: ["파이썬 MySQL 조건 필터"]
duplicate_of: ""
source_trust_level: "B"
confidence_score: 0.9
created_at: 2026-07-04
updated_at: 2026-07-04
review_reason: ""
merge_history: []
tags: ["python", "mysql", "w3schools", "where", "sql-injection", "like"]
raw_sources: ["https://www.w3schools.com/python/python_mysql_where.asp"]
applied_in: []
github_commit: ""
---
# [[Python MySQL Where]]
## 🎯 한 줄 통찰 (One-line insight)
When a filter value comes from user input, it must be passed as a bound `%s` parameter to `execute()` rather than string-concatenated into the SQL — the exact SQL-injection defense taught earlier, now shown in the mysql.connector API. [S1]
## 🧠 핵심 개념 (Core concepts)
- **WHERE filter** — `sql = "SELECT * FROM customers WHERE address ='Park Lane 38'"`. [S1]
- **Wildcard with `LIKE`** — `%` represents any characters: `WHERE address LIKE '%way%'`. [S1]
- **SQL injection prevention** — escape user-provided values via the `%s` placeholder and pass them as a tuple to `execute(sql, val)`, rather than concatenating strings. [S1]
## 🧩 추출된 패턴 (Extracted patterns)
- **This is [[SQL Injection]] and [[SQL Parameters]] applied concretely** — the exact string-concatenation vulnerability and `%s`-placeholder fix from those SQL-category chapters reappear here in the mysql.connector Python API. [S1]
## 📖 세부 내용 (Details)
- Basic WHERE: `sql = "SELECT * FROM customers WHERE address ='Park Lane 38'"`. [S1]
- Wildcard search: `sql = "SELECT * FROM customers WHERE address LIKE '%way%'"`. [S1]
- Injection-safe parameterized query: `sql = "SELECT * FROM customers WHERE address = %s"; adr = ("Yellow Garden 2",); mycursor.execute(sql, adr)`. [S1]
## ⚖️ 모순 및 업데이트 (Contradictions & updates)
소스에서 모순되는 정보는 발견되지 않음.
## 🛠️ 적용 사례 (Applied in summary)
현재 발견된 실제 적용 사례가 없습니다 — 사용자 입력을 쿼리에 넣어야 하는 모든 상황에서 %s 파라미터화가 표준 방어책이다. [S1]
## 💻 코드 패턴 (Code patterns)
Parameterized WHERE to prevent injection (Python):
```python
sql = "SELECT * FROM customers WHERE address = %s"
adr = ("Yellow Garden 2", )
mycursor.execute(sql, adr)
```
## ✅ 검증 상태 및 신뢰도
- **상태:** draft
- **검증 단계:** conceptual
- **출처 신뢰도:** B (W3Schools — widely used educational reference, not a primary standards body)
- **신뢰 점수:** 0.90
- **중복 검사 결과:** 신규 생성 (New discovery)
## 🔗 지식 그래프 (Knowledge Graph)
- **상위/루트:** [[Python Tutorial]]
- **관련 개념:** [[SQL Injection]], [[SQL Parameters]], [[Python MySQL Select]]
- **참조 맥락:** SQL Injection 방어의 mysql.connector 구현 — 사용자 입력을 다룰 때 항상 %s 파라미터화 사용.
## 📚 출처 (Sources)
- [S1] W3Schools — Python MySQL Where — https://www.w3schools.com/python/python_mysql_where.asp
## 📝 변경 이력 (Change history)
- 2026-07-04: Initial draft synthesized from the W3Schools "Python MySQL Where" page (Astra wiki-curation, P-Reinforce v3.1 format).