5 ms·
>> How are you turning the user supplied string into the SQL string literal string? Is your method for doing so guaranteed to always produce a valid SQL string
by paulasmuth 10y ago
>> How are you turning the user supplied string into the SQL string literal string? Is your method for doing so guaranteed to always produce a valid SQL string literal which represents the supplied string?
Yes. This is trivial. Any self-respecting junior programmer should be able to write this routine.
- biot 10y agoMake sure that junior programmer is a true Scotsman as well since they're more likely to have an apostrophe in their name.
- jameshart 10y agoWith respect, most junior programmers, whether self respecting or otherwise, would have trouble even recognizing that there is a need to cover some of those cases I mentioned, let alone successfully accommodating them. Most likely you'll get a return "'" + replace(str, "'", "\\'") + "'" which only after the first bug report gets turned into a return "'" + replace(replace(str,"\\","\\\\"),"'","\\'") + "'" and that will have been arrived at after a lot of trial and error and incorrect numbers of backslashes. And if you think that is robust, you're likely in for a surprise when someone sends you some unicode data.