in reply to DBIx::Class field name (identifier) injections

Ok, this isn't really the right place to bring this up at all (we have a mailing list.) But, the short answer is you are correct, nothing more is done than the naive quoting. I would recommend posting an RT, but realize that to do what you are asking for correctly requires the long awaited SQLA2, as every part of the query would need to be aware of what columns are in what table. So, again, please post an RT, but don't hold your breath.
fREW Schmidt
http://blog.afoolishmanifesto.com
  • Comment on Re: DBIx::Class field name (identifier) injections