From: David Vallner Date: 2006-10-26T07:27:26+09:00 Subject: Re: ruby mysql errors -where am I going wrong here? --------------enig8694973BB4CFDCC937FE681D Content-Type: text/plain; charset=ISO-8859-1 Content-Transfer-Encoding: quoted-printable Hugh Sasse wrote: > MySQL needs backticks `` for strings. Coming from Unix this was someth= ing > I didn't expect. Since it works for the strings 'check', that's obviously not the problem.= Also, I'd use a database API that supports parameter placeholders and does query escaping for you. Interpolating a string to get a SQL query is Bad (tm). Google around for "sql injection", "pain", "anguish", "death" (right, some of those aren't really related). If anything, use Mysql.escape on strings first at the very least. David Vallner --------------enig8694973BB4CFDCC937FE681D Content-Type: application/pgp-signature; name="signature.asc" Content-Description: OpenPGP digital signature Content-Disposition: attachment; filename="signature.asc" -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.5 (MingW32) iD8DBQFFP+THy6MhrS8astoRAqpqAJ9Se7RfsVaNF5/NFogqrJdK2LqXOwCbBNXq C0896bAlzWjr7llqyfBS2Go= =o+Ty -----END PGP SIGNATURE----- --------------enig8694973BB4CFDCC937FE681D--