← Back to Issue

Use bind parameters for array-form arguments in find_by_sql / count_by_sql

From uloza+hey@proton.me · original ↗ · unsubscribe

The API doc claims parity with where, but array-form values were eagerly interpolated via sanitize_sql.


Use bind parameters for array-form arguments in `find_by_sql` / `count_by_sql` by kamipo · Pull Request #58427 · rails/rails · GitHub

Skip to content

Sign in

Appearance settings

Search/

Sign in

Sign up

Appearance settings

You signed in with another tab or window. Reload to refresh your session. You signed out in another tab or window. Reload to refresh your session. You switched accounts on another tab or window. Reload to refresh your session. Dismiss alert

Uh oh!

There was an error while loading. Please reload this page.

rails / rails Public

Additional navigation options

Use bind parameters for array-form arguments in find_by_sql / count_by_sql - #58427

#58427

Merged

kamipo merged 1 commit into

rails:mainrails/rails:mainfrom

kamipo:refactor_find_by_sql_placeholder_generationkamipo/rails:refactor_find_by_sql_placeholder_generationCopy head branch name to clipboard

Aug 9, 2026

ConversationCommits1 (1)ChecksFiles changed

Merged

##

Use bind parameters for array-form arguments in find_by_sql / count_by_sql#58427

kamipo merged 1 commit into

rails:mainrails/rails:mainfrom

kamipo:refactor_find_by_sql_placeholder_generationkamipo/rails:refactor_find_by_sql_placeholder_generationCopy head branch name to clipboard

Conversation

@kamipo

###

@kamipokamipo commented Aug 9, 2026

Copy link

Copy Markdown

Member

The API doc claims parity with where, but array-form values were eagerly interpolated via sanitize_sql. Route them through Arel::Nodes::BoundSqlLiteral and consolidate the placeholder dispatch shared with build_where_clause into Sanitization#bound_sql_literal_for.

Sorry, something went wrong.

Uh oh!

There was an error while loading. Please reload this page.

All reactions @github-actions github-actions Bot added the activerecord label Aug 9, 2026

@kamipo

kamipo force-pushed the refactor_find_by_sql_placeholder_generation branch from d3e476d to 861107d Compare August 9, 2026 18:25

@kamipo

[Use bind parameters for array-form arguments in `find_by_sql` / `coun…](/rails/rails/pull/58427/commits/8c4ed25f0aa80f6067a358731fd5782be3817952 "Use bind parameters for array-form arguments in `find_by_sql` / `count_by_sql` The API doc claims parity with `where`, but array-form values were eagerly interpolated via `sanitize_sql`. Route them through `Arel::Nodes::BoundSqlLiteral` and consolidate the placeholder dispatch shared with `build_where_clause` into `Sanitization#bound_sql_literal_for`.") …

[8c4ed25](/rails/rails/pull/58427/commits/8c4ed25f0aa80f6067a358731fd5782be3817952)

…t_by_sql`

The API doc claims parity with `where`, but array-form values were eagerly interpolated via `sanitize_sql`. Route them through `Arel::Nodes::BoundSqlLiteral` and consolidate the placeholder dispatch shared with `build_where_clause` into `Sanitization#bound_sql_literal_for`.

@kamipo

kamipo force-pushed the refactor_find_by_sql_placeholder_generation branch from 861107d to 8c4ed25 Compare August 9, 2026 18:34

Hide details View details

@kamipo

kamipo merged commit adf307b into rails:main Aug 9, 2026

5 checks passed

Uh oh!

There was an error while loading. Please reload this page.

@kamipo

kamipo deleted the refactor_find_by_sql_placeholder_generation branch August 9, 2026 19:57

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

### Reviewers

No reviews

Assignees

No one assigned

Labels

activerecord

Projects

None yet

Milestone

No milestone

Development

Successfully merging this pull request may close these issues.

Uh oh!

There was an error while loading. Please reload this page.

1 participant

@kamipo

Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

© 2026 GitHub, Inc.

You can’t perform that action at this time.

Highlights & notes

    Notes