FW: Entering ' or " with informix.....
Posted in 1998
> It still can cause problems with sql statements, and I don't allow
> them in my database. At the very lease you should pick one and
> disallow the other. Suppose you prepare a statement like the following
>
> 'select * from table where field1 = ', prog_variable
>
> and prog_variable has had the value of Le'Hermatige selected into it
> earlier.
>
> The prepare statement will bomb out at runtime. If you are consistent
> in your programs and use either ' or " only, then the users can use
> the other. But I can see where your vendor is coming from.
> -----Original Message-----
> From: Art S. Kagel [SMTP:kagel@bloomberg.net]
> Posted At: Wednesday, June 17, 1998 4:40 PM
> Posted To: Informix
> Conversation: Entering ' or " with informix.....
> Subject: Re: Entering ' or " with informix.....
>
> pmilitzer@ultracom.com wrote:
> >
> > Hi there,
> >
> > Is it possible to put a quote or double quote in a field in informix
> > 7.23. ? An example of this would be: Le' Hermatige . Is this a
> > problem with informix? Our vendor says it can't be done cause it
> > screws up the SQL statements.
>
> It certainly CAN be done. You just have to be careful to use the
> other
> quote character to quote the string and even this is not a real
> problem
> using 4GL or ESQL/C. On the other hand it can certainly cause you
> much
> grief. For example, picture a comment column containing:
>
> <Mister O'Brien said, "I did not say that that's what happened!">
>
> Now for this string there is no way in DBACCESS to enter the string
> because neither single nor double quotes can be used to surround the
> string because it contains both quotation characters. Again not a
> problem in 4GL or ESQL/C or even for dbload or the dbaccess load verb.
>
> Hmm. Looks like your vendor is just lazy to me!
>
> Art S. Kagel