Skip to the content.

Dapper allows writing parameterized queries, but developer should never interpolate values into the query string (sql parameter for any Dapper-method).

Bad:

var id = 42;
conn.Execute($"select Id from Customers where Id = {id}");

Instead the intended way is to pass the anynomous object, members of which will be mapped into the query parameter using the same name.

In example for the object new { A = 42, B = "hello world" }:

Good:

var id = 42;
conn.Execute(
	$"select Id from Customers where Id = @queryId",
	new { queryId = id }
);