- Joined
- Mar 1, 2023
- Messages
- 24
- Reaction score
- 1
CONCATENATE("select * from table where id = '",myVariable,"'")select * from table where id = @idYou can't use the CONCATENATE expression anymore with the Database Access component. You must use parameters instead. This is to avoid SQL injection.

select * from table where id = @id
The table name is static, so you don't need to set it as a parameter. The statement should be:Is there any updated documentation about this anywhere? I have a CFD app I'm trying to update that uses the database access component as well, and I can't seem to get past the same error as Sovuthy.
The SQL statement was originally: CONCATENATE("SELECT count(*) FROM \"JPAssetSites\" WHERE \"propID\"=",inputPropID.Buffer)
And it has been changed to: SELECT count(*) FROM @table WHERE propID = @propertyID
I added 2 parameters as well - table = "JPAssetSites", and propertyID = inputPropID.Buffer
The error I am seeing on build is: Error: SQL Statement must be a constant string value at Database Access component 'authPropID'. Please use parameters for variable parts to avoid SQL injection. (file Main.flow)
I appreciate any advice you may have.
"SELECT count(*) FROM \"JPAssetSites\" WHERE \"propID\"=@propertyID"propertyIDinputPropID.BufferTO_STRING function.CONCATENATE function in the SQL statement, just what I suggested above.That fixed it, thank you. I removed the quotes and escape characters because I thought they were only needed by the concatenate function. Putting them back seems to be doing the job. Much appreciated!The table name is static, so you don't need to set it as a parameter. The statement should be:
"SELECT count(*) FROM \"JPAssetSites\" WHERE \"propID\"=@propertyID"
Then you need to define just 1 parameter:
propertyID
Set it to:
inputPropID.Buffer
The Buffer property is already a string, so you don't need to use theTO_STRINGfunction.
You can't use theCONCATENATEfunction in the SQL statement, just what I suggested above.
Founded in 2005, when VoIP was an emerging technology, 3CX has gone on to establish itself as a global leader in business communications.