Live data from Hacker News

Similarity in Postgres and Rails Using Trigrams

pganalyze.com

1–10 of 10 posts

Re: Similarity in Postgres and Rails Using Trigrams

#6
I'm somewhat confused why the author didn't use bind variables since as far as I know the standard PostgreSQL adapters fully support them. Even if you trust that quote_string() will never have a vulnerability it's safer to not use string interpolation at all and it doesn't cost you anything.

Re: Similarity in Postgres and Rails Using Trigrams

#9
I used this to replace an aging ElasticSearch implementation our company was using. Simple and fast, and 1 less piece of tech in the stack to maintain. Postgres really is a brilliant piece of software. Yeah I know paid solutions which arguably work better exist, but for a "free" product Postgres does astoundingly well in many areas.

Re: Similarity in Postgres and Rails Using Trigrams

#10
post #6

I'm somewhat confused why the author didn't use bind variables since as far as I know the standard PostgreSQL adapters fully support them. Even if you trust that quote_string() will never have a vulnerability it's safer to not use string interpolation at all and it doesn't cost you anything.

(not the author, but I've discussed this with him previously)

This is a problem with `order` in Active Record in particular, where you can't pass in a bind variable the same way you'd expect it to work with `where`.

Therefore the slightly less elegant version that goes through quote_string. You could use bind variables by going directly to the pg driver, but I think there is no quick shorthand to do this in Active Record/Arel.