0%

Change Data Safely · practice

Insert One New Item

The lending catalog needs a new repair kit. Python already has the complete item as one , and the database should store those five values without turning any text inside them into SQL.

Run will make this exact call through an open catalog connection:

add_item(connection, (7, "KT-700", "Repair kit", "tools", 5))

The tuple positions are id, asset_tag, name, category, and loan_days. Open catalog_changes.py and find the new below find_item:

def add_item(connection, item):
    statement = """
        INSERT INTO items (id, asset_tag, name, category, loan_days)
        VALUES (?, ?, ?, ?, ?)
    """
    connection.execute(statement)

INSERT INTO items names the table that will receive a row. The explicit column fixes the meaning and order of all five values. VALUES provides five placeholder positions, one for each named column.

The mapping is worth checking before you edit:

Column and placeholder position in item
id, first ?first tuple value
asset_tag, second ?second tuple value
name, third ?third tuple value
category, fourth ?fourth tuple value
loan_days, fifth ?fifth tuple value

For the visible call, that means the database receives 7 for id, "KT-700" for asset_tag, "Repair kit" for name, "tools" for category, and 5 for loan_days. Nothing needs to be joined, quoted, or converted first. The statement describes the operation; the tuple already contains the row. Keeping that one-to-one mapping visible also makes mistakes easier to spot: five named columns, five placeholders, and five values in the same order.

Change the final line so the complete tuple travels as the separate values :

connection.execute(statement, item)

Press Run. The function currently returns None, which is fine for this exercise. The important evidence appears below it:

item with tag KT-700
(7, 'KT-700', 'Repair kit', 'tools', 5)
unchanged neighbor EL-300
(5, 'EL-300', 'Projector', 'electronics', 2.5)

The inserted row comes back unchanged through the same open connection, and an existing neighbor is still intact. For now, you are only checking what that open connection can see. You will make changes survive closing and reopening a connection later.

Submit tries unseen IDs, apostrophes, SQL-looking text, and positive fractional periods. Keep every value in the separate tuple. Do not omit the explicit ID, rearrange tuple positions, or open another connection inside the function.

You have carried the safe value boundary from one search value to a complete new catalog row: fixed SQL on one side, five unchanged Python values on the other.

Task

In add_item, pass item as the second to connection.execute(statement, item). Keep the explicit five-column INSERT and five placeholders unchanged.

Run the project, confirm the new row and neighbor, then submit the .