--- id: python-mysql-where title: "Python MySQL Where" category: "Programming_Language" status: "draft" verification_status: "conceptual" canonical_id: "" aliases: ["파이썬 MySQL 조건 필터"] duplicate_of: "" source_trust_level: "B" confidence_score: 0.9 created_at: 2026-07-04 updated_at: 2026-07-04 review_reason: "" merge_history: [] tags: ["python", "mysql", "w3schools", "where", "sql-injection", "like"] raw_sources: ["https://www.w3schools.com/python/python_mysql_where.asp"] applied_in: [] github_commit: "" --- # [[Python MySQL Where]] ## 🎯 한 줄 통찰 (One-line insight) When a filter value comes from user input, it must be passed as a bound `%s` parameter to `execute()` rather than string-concatenated into the SQL — the exact SQL-injection defense taught earlier, now shown in the mysql.connector API. [S1] ## 🧠 핵심 개념 (Core concepts) - **WHERE filter** — `sql = "SELECT * FROM customers WHERE address ='Park Lane 38'"`. [S1] - **Wildcard with `LIKE`** — `%` represents any characters: `WHERE address LIKE '%way%'`. [S1] - **SQL injection prevention** — escape user-provided values via the `%s` placeholder and pass them as a tuple to `execute(sql, val)`, rather than concatenating strings. [S1] ## 🧩 추출된 패턴 (Extracted patterns) - **This is [[SQL Injection]] and [[SQL Parameters]] applied concretely** — the exact string-concatenation vulnerability and `%s`-placeholder fix from those SQL-category chapters reappear here in the mysql.connector Python API. [S1] ## 📖 세부 내용 (Details) - Basic WHERE: `sql = "SELECT * FROM customers WHERE address ='Park Lane 38'"`. [S1] - Wildcard search: `sql = "SELECT * FROM customers WHERE address LIKE '%way%'"`. [S1] - Injection-safe parameterized query: `sql = "SELECT * FROM customers WHERE address = %s"; adr = ("Yellow Garden 2",); mycursor.execute(sql, adr)`. [S1] ## ⚖️ 모순 및 업데이트 (Contradictions & updates) 소스에서 모순되는 정보는 발견되지 않음. ## 🛠️ 적용 사례 (Applied in summary) 현재 발견된 실제 적용 사례가 없습니다 — 사용자 입력을 쿼리에 넣어야 하는 모든 상황에서 %s 파라미터화가 표준 방어책이다. [S1] ## 💻 코드 패턴 (Code patterns) Parameterized WHERE to prevent injection (Python): ```python sql = "SELECT * FROM customers WHERE address = %s" adr = ("Yellow Garden 2", ) mycursor.execute(sql, adr) ``` ## ✅ 검증 상태 및 신뢰도 - **상태:** draft - **검증 단계:** conceptual - **출처 신뢰도:** B (W3Schools — widely used educational reference, not a primary standards body) - **신뢰 점수:** 0.90 - **중복 검사 결과:** 신규 생성 (New discovery) ## 🔗 지식 그래프 (Knowledge Graph) - **상위/루트:** [[Python Tutorial]] - **관련 개념:** [[SQL Injection]], [[SQL Parameters]], [[Python MySQL Select]] - **참조 맥락:** SQL Injection 방어의 mysql.connector 구현 — 사용자 입력을 다룰 때 항상 %s 파라미터화 사용. ## 📚 출처 (Sources) - [S1] W3Schools — Python MySQL Where — https://www.w3schools.com/python/python_mysql_where.asp ## 📝 변경 이력 (Change history) - 2026-07-04: Initial draft synthesized from the W3Schools "Python MySQL Where" page (Astra wiki-curation, P-Reinforce v3.1 format).