Change Data Safely · capstone
Capstone project: Project: Build Safe Member Change Functions
The member table needs the same careful operations you built for items. This time you will choose all four statements and
Each member row has this exact order:
| Position | Column | Example |
|---|---|---|
| 1 | id | 13 |
| 2 | member_code | "M'50" |
| 3 | name | "Ari O'Neil" |
| 4 | loan_limit | 2.5 |
Open member_changes.py. It contains four
find_member(connection, member_code)selectsid, member_code, name, loan_limitfor one bound code and returns.fetchone().add_member(connection, member)inserts the four explicit columns with four placeholders and returns the insert cursor’s immediaterowcount.change_loan_limit(connection, member_code, loan_limit)updatesloan_limitwhere the bound code matches. Its values are(loan_limit, member_code), and it returns immediaterowcount.remove_member(connection, member_code)deletes where the bound code matches and returns immediaterowcount.
Write a fixed triple-quoted statement inside each function, then call connection.execute(statement, values) through the supplied open connection. Do not open, close, or replace that connection.
A useful order is search, insert, update, then delete. The four parameter
| Function | Values passed beside the statement |
|---|---|
find_member | (member_code,) |
add_member | member |
change_loan_limit | (loan_limit, member_code) |
remove_member | (member_code,) |
For a code such as "M'50", the apostrophe stays inside the Python value in each case. It never becomes part of the SQL text, so searching, changing, and removing that member all use the same safe boundary.
Run demonstrates one complete sequence with literal calls. It finds Riley, then calls:
add_member(connection, (13, "M'50", "Ari O'Neil", 2.5))
change_loan_limit(connection, "M'50", 4.5)
remove_member(connection, "M'50")
The expected returns are 1, 1, and 1. Searches before and after show the complete tuple, its changed limit, and finally None. The same open connection carries every observation.
The run also uses "X' OR 1=1 --" as a missing code. Both change functions should return 0, and Sam’s M-23 row must remain unchanged. Preserve each complete code as a bound value.
Submit tests every function separately and in sequence with unseen IDs, names, apostrophes, SQL-looking text, and positive whole and fractional limits. The table’s existing rules may raise their normal database error for duplicate IDs, duplicate codes, or invalid limits; do not hide or relabel those errors.
Work one function at a time. First make its ordinary case visible, then check the missing or hostile-looking value, and only then move on. The finished
Task
Implement all four member_changes.py using fixed SQL and separate bound values. Return a None from find_member, and immediate integer rowcounts from add, update, and remove.
Run the complete member sequence, verify the unchanged neighbor, and submit the