# Rails Direct SQL

**URL:** <https://forum.kirupa.com/t/rails-direct-sql/212953>\
**Category:** programming\
**Created:** [January 15, 2007, 11:12pm UTC](https://forum.kirupa.com/t/rails-direct-sql/212953 "2007-01-15T23:12:41Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![Jeff\_Wheeler](https://avatars.discourse-cdn.com/v4/letter/j/59ef9b/32.png) [@Jeff\_Wheeler](https://forum.kirupa.com/u/Jeff_Wheeler)\
**Post date:** [January 15, 2007, 11:12pm UTC](https://forum.kirupa.com/t/rails-direct-sql/212953/1 "2007-01-15T23:12:41Z")

</div>

Yuck, please tell me this is not really the case.

In my Rails book, they do:

```auto
Order.find(:all, :conditions=>"name='dave'").each do |order|
  puts order.amount
end

```

Ignoring the fact that they used the slower double-quotes instead of single-quotes, “name=‘dave’” is stuffed directly into the SQL command, isn’t it?

Or, can I use something like hashes to do it more semantically?

```auto
Order.find(:all, :conditions=>{'name':'dave'}).each do |order|
  puts order.amount
end

```

(Not sure about the exact source, but you get the point…)

If that’s really the case, that alone almost makes me want to not use Rails… yucky, yucky, yucky. Why would they do that?!
