3 ms·
I can't tell if you're trolling or not, but this is not how string escaping works in SQL or any other programming language that I know. >> SELECT 'here is
by paulasmuth 10y ago
I can't tell if you're trolling or not, but this is not how string escaping works in SQL or any other programming language that I know.
>> SELECT 'here is an apostrophe: \'';
>> returns: here is an apostrophe: '
The backslash is not part of the string but just a hint to the compiler. The literal string '\'' represents a one byte (if ASCII) string containing only a single apostrophe character.
https://en.wikipedia.org/wiki/Escape_character https://en.wikipedia.org/wiki/Escape_character
- jameshart 10y agoThere's a difference between saying that Gijs in \'t Veld is a 'sanitized' version of Gijs in 't Veld and saying that 'Gijs in \'t Veld' is a SQL String literal representing the string Gijs in 't Veld
- Scarblac 10y agoI meant that if you were to "sanitize" all input your program gets by replacing "'" by "\'" in there everywhere, then assuming that most of the rest of your program actually works as normal and calls libraries that do things correctly etc, you're just going to have backslashes show up because they're in the string. Maybe you also echo the string back to HTML immediately before it ever goes into SQL, et cetera. Only escaping quotes that are inserted directly into SQL query strings is not what I understood by "sanitizing all input".