Template parameters save you from typing one value in four places, but they only paste text. Here is what that means in practice.
XML modify(): Inserting, Replacing and Deleting Nodes
The modify() method edits XML in place, but a path that matches nothing changes nothing and says nothing. Here is how to stay in control.
Dynamic ORDER BY Without Injection: Whitelisting Sort Columns
Parameters cannot name a column, so grids end up gluing text into SQL. Here is the approved-list pattern that keeps the sort safe.
SQL SERVER – Quiz and Video – Introduction to Hierarchical Query using a Recursive CTE
Learn to write a hierarchical query using a recursive CTE with a short video and a quiz on an employee and manager table. Check your answer.
SQL SERVER – Quiz and Video – Introduction to SQL Server Security
A follow up to my primer on SQL Server security, with a short quiz and a video on three key ideas: granting, denying and revoking permissions.
Word Search Without Full-Text: Build a Word Index Table
LIKE with a leading wildcard reads the whole table. A small side table of words turns that scan into a quick lookup, and you do not need full-text installed.







