Files
2nd/10_Wiki/Dev/Topic_Python/Python_MySQL_Where.md
T
Antigravity Agent 1cfd3bbb56 docs(10_Wiki): 위키 구조 정리 — 언어 튜토리얼 카테고리 폴더 제거 + 신규 자산 동기화
Topic_CSS/Topic_HTML/Topic_JavaScript/Topic_Prompt/Topic_Comfyui 등 기존 카테고리 폴더를 정리하고,
Topic_Graphic/Dev 등 신규 산출물과 Topics 내부 세션/메모리 기록을 동기화.
2026-07-05 00:10:59 +09:00

3.2 KiB

id, title, category, status, verification_status, canonical_id, aliases, duplicate_of, source_trust_level, confidence_score, created_at, updated_at, review_reason, merge_history, tags, raw_sources, applied_in, github_commit
id title category status verification_status canonical_id aliases duplicate_of source_trust_level confidence_score created_at updated_at review_reason merge_history tags raw_sources applied_in github_commit
python-mysql-where Python MySQL Where Programming_Language draft conceptual
파이썬 MySQL 조건 필터
B 0.9 2026-07-04 2026-07-04
python
mysql
w3schools
where
sql-injection
like
https://www.w3schools.com/python/python_mysql_where.asp

Python MySQL Where

🎯 한 줄 통찰 (One-line insight)

When a filter value comes from user input, it must be passed as a bound %s parameter to execute() rather than string-concatenated into the SQL — the exact SQL-injection defense taught earlier, now shown in the mysql.connector API. [S1]

🧠 핵심 개념 (Core concepts)

  • WHERE filtersql = "SELECT * FROM customers WHERE address ='Park Lane 38'". [S1]
  • Wildcard with LIKE% represents any characters: WHERE address LIKE '%way%'. [S1]
  • SQL injection prevention — escape user-provided values via the %s placeholder and pass them as a tuple to execute(sql, val), rather than concatenating strings. [S1]

🧩 추출된 패턴 (Extracted patterns)

  • This is SQL Injection and SQL Parameters applied concretely — the exact string-concatenation vulnerability and %s-placeholder fix from those SQL-category chapters reappear here in the mysql.connector Python API. [S1]

📖 세부 내용 (Details)

  • Basic WHERE: sql = "SELECT * FROM customers WHERE address ='Park Lane 38'". [S1]
  • Wildcard search: sql = "SELECT * FROM customers WHERE address LIKE '%way%'". [S1]
  • Injection-safe parameterized query: sql = "SELECT * FROM customers WHERE address = %s"; adr = ("Yellow Garden 2",); mycursor.execute(sql, adr). [S1]

⚖️ 모순 및 업데이트 (Contradictions & updates)

소스에서 모순되는 정보는 발견되지 않음.

🛠️ 적용 사례 (Applied in summary)

현재 발견된 실제 적용 사례가 없습니다 — 사용자 입력을 쿼리에 넣어야 하는 모든 상황에서 %s 파라미터화가 표준 방어책이다. [S1]

💻 코드 패턴 (Code patterns)

Parameterized WHERE to prevent injection (Python):

sql = "SELECT * FROM customers WHERE address = %s"
adr = ("Yellow Garden 2", )
mycursor.execute(sql, adr)

검증 상태 및 신뢰도

  • 상태: draft
  • 검증 단계: conceptual
  • 출처 신뢰도: B (W3Schools — widely used educational reference, not a primary standards body)
  • 신뢰 점수: 0.90
  • 중복 검사 결과: 신규 생성 (New discovery)

🔗 지식 그래프 (Knowledge Graph)

📚 출처 (Sources)

📝 변경 이력 (Change history)

  • 2026-07-04: Initial draft synthesized from the W3Schools "Python MySQL Where" page (Astra wiki-curation, P-Reinforce v3.1 format).