Home Forums SQL Server 2008 T-SQL (SS2K8) Eliminate Dynamic SQL - WHERE Clause RE: Eliminate Dynamic SQL - WHERE Clause
getoffmyfoot
Hall of Fame
Points: 3338
More actions
October 5, 2010 at 11:37 am
#1231934
dynamic sql is also more susceptible to sql injection. you might find it cleaner to have 2 queries with different formatted where clauses and an if statement that chooses which sql statement to run.