# Coding "conditions" for SQL statements

**URL:** <https://forum.kirupa.com/t/coding-conditions-for-sql-statements/319079>\
**Category:** flash\
**Created:** [February 8, 2011, 12:23pm UTC](https://forum.kirupa.com/t/coding-conditions-for-sql-statements/319079 "2011-02-08T12:23:29Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![IQAndreas](https://avatars.discourse-cdn.com/v4/letter/i/f08c70/32.png) [@IQAndreas](https://forum.kirupa.com/u/IQAndreas)\
**Post date:** [February 8, 2011, 12:23pm UTC](https://forum.kirupa.com/t/coding-conditions-for-sql-statements/319079/1 "2011-02-08T12:23:29Z")

</div>

I thought I may make a few “helper” classes for writing SQL (both in AS3 for AIR and PHP) but I keep running into a problem.

First, this is the class that works just fine in my mind:

```auto
var details:String = "I like to hack! '; DROP TABLE users WHERE (1);--";
new SQLInsert(db.tables.users, {first_name:"Andreas", last_name:"Renberg", details:details, emailNotifications:true, registered:new Date()});

```

The insert will automatically escape the necessary characters, since there is a _clear_ separation between field names and values.

The problem comes in with the “WHERE” part. I can’t find any good way of coding it without making the “conditions” into Strings. I don’t like that. ☹

```auto
var where:SQLWhere = new SQLWhere("id=5", "age>40", "banned=false");
new SQLSelect(["id", "first_name", "last_name"], where);

```

Also, I don’t like using an array of strings in the first part of the SELECT, but oh well. That one seems unavoidable. 😕
