Python Database
Priority: P1 (HIGH)
Rules
- Parameterize every query; never interpolate user or runtime data into SQL strings.
- Keep connection and transaction ownership explicit.
- Hide storage shape behind repository or query helpers when business logic depends on it.
- Normalize JSON and null handling at the persistence boundary.
Recipe
- Open connections through one helper or pool abstraction.
- Use context managers for connection and transaction lifetime.
- Keep one business action in one transaction.
- Return typed rows or normalized dicts, not raw cursor tuples leaking everywhere.
- Test malformed/null metadata paths when patching JSON payloads.
Anti-Patterns
- No f-string SQL.
- No transaction split-brain across handler, service, and repo.
- No unbounded connection churn in loops.
- No DB truth hidden behind report formatting code.
References
- Framework Map
- DB Boundaries