Glossary · Term

prepared statement

← all terms

Definition

Plain language

A way of talking to a database that keeps the command and the user-supplied data in separate envelopes so the data can never become a command.

As stated in the literature

A parameterized database query in which SQL structure is transmitted and compiled independently of the bound values, eliminating SQL injection by carrying structure out-of-band rather than by sanitizing text.

Also called: prepared statements

Why it matters: It is the proven fix for an entire class of injection attacks, and it works by separating instructions from data rather than by trying to spot dangerous text.

For example, a login form sends the query shape "find the user whose name equals ?" and the typed name separately, so a visitor who types a fragment of database code just gets treated as a very odd username.

Heard on the show

“But a language model’s context window doesn’t have an equivalent of a prepared statement.”
Episode 250 — The Same Model Refused a Backdoor, Then Its Own Sub-Agent Ran It

Related terms