On Thu, 3 Sept 2026 at 19:52, Peter J. Holzer <[email protected]> wrote: > Pros: > > * it looks very clean > * it makes the code shorter > * The names of the placeholders are always in sync with the names of > local variables > > Cons: > > * Less explicit, so it may not be as obvious what the parameters are > * All local variables are exposed to execute, not just those it needs > > What do you guys think? >
It increases risks, since other locals become available; and it can only handle true locals rather than other types of name you could look up. But if you can depend on a reasonably recent version of Python, there's a much better option: t-strings. https://docs.python.org/3.14/library/string.templatelib.html#template-strings They capture *any* type of name lookup, and can be relatively easily turned into viable (and safe) SQL queries. ChrisA -- https://mail.python.org/mailman3//lists/python-list.python.org
