Por enquanto, esta lição está em inglês.
Never let input write your SQL
One string concatenation can hand your whole database to an attacker. SQL injection is decades old and still one of the most common web attacks. In Go the fix is simple, and you already know it.