Re: SQL from the command line
Posted in 1995
I've seen a couple of responses which seem to go off at a tangent to the
question asked, so here's my answer which is, I hope, more to the point.
}From: Andy Cordell <andy@bnr.ca>
}Date: 21 Feb 1995 21:29:54 GMT
}X-Informix-List-Id: <news.11700>
}
}What is the proper way to provide a SQL command line interface to
}a user without making them create a sql command file to issue a
}command? What I'd like is the ability to type something like
}this on the unix command line:
}
}<dbname> <SQL command here>
}The response would come back to stdout.
}
}This is the almost working script that I wrote:
}
}#! /bin/sh
}echo "$@" > temp.sql
}dbaccess -e <dbname> temp.sql
}
}The only problem with this is that it expands the * in
}"select * from <table> " to be the current directory listing, so
}I end up with :
}select <insert really big directory listing here> from <table>
}as my SQL command, which is not good.
This is not an Informix problem but a shell problem. The * on the command
line would have to be escaped somehow so that the shell does not do the
expansion. I'd use quotes around the whole command:
sqlcmd -d dbase -e "select * from systables where tabname = 'systables'"
sqlcmd -d dbase -e 'select * from systables where tabname = "systables"'
Your script is a reasonable starting point for exactly that sort of
processing. The rest is education of the user.
}Is this the right approach? Is there already a utility that will
}provide SQL statements (not cmd files) from the command line?
You can dig my ESQL/C program SQLCMD out of the archives. It uses exactly
the notation I used above. But even it cannot protect users from the
shell.
Yours,
Jonathan Leffler (johnl@informix.com) #include <disclaimer.h>