Python Sqlite3: INSERT INTO table VALUE(dictionary goes here)

后端 未结 9 518
野趣味
野趣味 2020-12-24 12:26

I would like to use a dictionary to insert values into a table, how would I do this?

import sqlite3

db = sqlite3.connect(\'local.db\')
cur = db.cursor()

c         


        
9条回答
  •  生来不讨喜
    2020-12-24 12:38

    If you're trying to use a dict to specify both the column names and the values, you can't do that, at least not directly.

    That's really inherent in SQL. If you don't specify the list of column names, you have to specify them in CREATE TABLE order—which you can't do with a dict, because a dict has no order. If you really wanted to, of course, you could use a collections.OrderedDict, make sure it's in the right order, and then just pass values.values(). But at that point, why not just have a list (or tuple) in the first place? If you're absolutely sure you've got all the values, in the right order, and you want to refer to them by order rather than by name, what you have is a list, not a dict.

    And there's no way to bind column names (or table names, etc.) in SQL, just values.

    You can, of course, generate the SQL statement dynamically. For example:

    columns = ', '.join(values.keys())
    placeholders = ', '.join('?' * len(values))
    sql = 'INSERT INTO Media ({}) VALUES ({})'.format(columns, placeholders)
    cur.execute(sql, values.values())
    

    However, this is almost always a bad idea. This really isn't much better than generating and execing dynamic Python code. And you've just lost all of the benefits of using placeholders in the first place—primarily protection from SQL injection attacks, but also less important things like faster compilation, better caching, etc. within the DB engine.

    It's probably better to step back and look at this problem from a higher level. For example, maybe you didn't really want a static list of properties, but rather a name-value MediaProperties table? Or, alternatively, maybe you want some kind of document-based storage (whether that's a high-powered nosql system, or just a bunch of JSON or YAML objects stored in a shelve)?


    An alternative using named placeholders:

    columns = ', '.join(my_dict.keys())
    placeholders = ':'+', :'.join(my_dict.keys())
    query = 'INSERT INTO my_table (%s) VALUES (%s)' % (columns, placeholders)
    print query
    cur.execute(query, my_dict)
    con.commit()
    

提交回复
热议问题