Kennedy Article on Rails Secuity
// ...
public function create_some_model($params) {
// Database handle setup to $dbh
$stmt = $dbh->prepare("INSERT INTO some_models (first_name, surname) VALUES (:first_name, :surname");
