Skip to content
Skip to the lesson
← RoadmapDay 45 of 90Backend & Data2h 30m

ORMs, the N+1 problem, and SQL injection

By the end of today you can read ORM code and know what SQL it will produce, spot an N+1 query before it reaches production, and explain why parameterised queries stop injection while escaping does not.

YesterdayDays 41 to 44 taught you tables, SQL, indexes and transactions. Today you meet the layer most code actually uses to reach them.

TomorrowTomorrow you consolidate the phase by designing a schema and defending it under pressure.

01

Why this matters

The N+1 problem is the most common database performance bug in application code, and it is invisible unless you know to look. SQL injection remains one of the most damaging vulnerabilities there is.

  • ORMs
  • The N+1 problem
  • SQL injection
  • What an abstraction hides
02

Learn it

80 min

Copy this into Claude or ChatGPT. It quizzes you before it explains anything, which is deliberate. The resources under it are how you check what it told you.

Today's Master Prompt

Free · sign in

A prompt written for this day alone: your level, the exact scope, what to leave out, and an instruction to quiz you before it explains anything. Paste it into Claude or ChatGPT and it teaches you today's material.

Sign in to continueNo card, now or later.

Check it against something that is not a model

An assistant can be fluent and wrong, and on a topic you met today you will not catch it. These cover the same ground and were made by people who do this for a living, so they are what you hold the explanation up against. They are other people's work and we only link to them, so judge them for yourself.

3 hand-picked resources

Free · sign in

Videos, official docs and articles covering the same ground, each opened and annotated by hand. They are what you check the assistant against on a day you cannot yet catch it being wrong.

Sign in to continueNo card, now or later.
03

Build it

50 min

Set up an ORM against your library schema with query logging on. Write a loop that reads every member and their loans, and count the queries. Then rewrite it with eager loading and count again. Separately, write a search endpoint with string concatenation, attack it with a payload that returns rows it should not, then fix it with parameters.

04

Recall it

20 min

Answer out loud, reveal, then mark honestly whether you had it. That score is the only thing on this page you do not get to choose.

5 recall questions

Free · sign in

Questions you answer from memory, then grade yourself against the real answer. The score is carried into the mastery rating below it, so an honest miss cannot quietly become a tick.

Sign in to continueNo card, now or later.
05

Rate it

Completion and mastery are tracked separately. Be honest, because an inflated rating only means the concept resurfaces sooner.

Mastery tracking

Free · sign in

Rate yourself against five named criteria per concept. Completion and mastery are tracked separately, and anything you rate shakily comes back automatically on a spaced schedule.

Sign in to continueNo card, now or later.
06

Recap

  • 01An ORM trades visibility for convenience
  • 02N+1 looks like an ordinary loop and shows up only in the query log
  • 03Parameterisation separates structure from data, so data cannot become structure
  • 04Dropping to raw SQL is a normal decision, not a failure

Your progress

Free · sign in

Mark days complete, pick up where you left off across devices, and watch completion and mastery diverge. Free, and the account exists only so ninety days of work cannot vanish with a cleared browser.

Sign in to continueNo card, now or later.