Please help =)
Posted in 1999
Topics: Stored Procedures & SPL
Newsgroup: I have forms on a database that my boss fills out to add items to a storefront. How can I have single quotes, double quotes, carriage returns, and such characters written to the database without causing an error. I can escape the characters fine on the URL string etc, but it still won't write to the database. If I have to I can parse all the entries with charAt and change the characters to ones that are not usually used such as | for carriage returns and { for single quotes and } for double quotes, but I'm hoping there is a solution that is higher quality. If not I will create functions to do this. Thanks a bunch! Eric ets3@email.byu.edu
Eric Shipek wrote: > I have forms on a database that my boss fills out to add items to a > storefront. How can I have single quotes, double quotes, carriage > returns, and such characters written to the database without causing > an error. I can escape the characters fine on the URL string etc, > but it still won't write to the database. > > If I have to I can parse all the entries with charAt and change the > characters to ones that are not usually used such as | for carriage > returns and { for single quotes and } for double quotes, but I'm > hoping there is a solution that is higher quality. If not I will > create functions to do this. What are you using to put the stuff into the database? The normal technique is to use a host variable containg the string, punctuation and all, and use a prepared statement with a place-holder or an unprepared statement referencing your variable: EXEC SQL INSERT INTO SomeTable VALUES(:str_value); EXEC SQL PREPARE p_insert FROM "INSERT INTO SomeTable VALUES(?)"; EXEC SQL EXECUTE p_insert USING :str_value; Of course, that is ESQl/C code with no variable decalaration; you will probably be using something else and will have to adapt this basic solution to your environment. If you're going to encode the data, do so unambiguously. Consider hex escapes: \\AA indicates that the character has hex code 0xAA. You then have to replace any actual backslashes with \\ZZ where ZZ is the hex code for back-slash (which I've forgotten...if I ever knew it:-). -- Jonathan Leffler (jleffler@informix.com, jleffler@earthlink.net) Guardian of DBD::Informix v0.60 -- see http://www.perl.com/CPAN #include <disclaimer.h>