Does Nhibernate 3.0 QueryOver handle SQL injections properly?
I know it's based off HQL so is it 开发者_C百科just using the same mechanisms that SetString, etc use?
Actually QueryOver is a strongly typed representation of the Criteria API, not the HQL API. Regardless, it sanitizes parameters.
精彩评论