Dynamic SQL
Posted in 1994
Tang Chang Thai — — source: Informix-list mailing list archive (1991-1998)
Hi ... I have this problem with dynamic SQL: If I need to insert into a table t1 with a single character field, one way to do it is as follows: sprintf (buffer, "insert into t1 values ('%s')", "Sample") and get buffer to be prepared and executed. In cases where the value is not static, ie the value "Sample" is actually user-supplied, then the string may contain characters like ', " and lf/cr. This character will then cause the buffer to be messed up which confuses the dynammic SQL mechanism. Is there any way to overcome this? .