3 ms·
No, you don't need to unescape it when displaying it. This SQL literal string: 'Gijs in \'t Veld' Is a representation for these ASCII bytes/content:
by paulasmuth 10y ago
No, you don't need to unescape it when displaying it.
This SQL literal string:
'Gijs in \'t Veld'
Is a representation for these ASCII bytes/content:
Gijs in 't Veld
In other words. The backslash will not be stored as part of the string into the database. It's just a hint to the SQL parser that the following single quote should be interpreted as a literal single quote char and not as the end-of-string-character.
From a security perspective there is nothing more "proper" about prepared queries than correctly escaped non-prepared queries.