From: David Masover Date: 2008-05-29T18:49:20+09:00 Subject: Re: Strings, postgresql and gsub On Thursday 29 May 2008 03:47:59 J-H Johansen wrote: > Hi, > > I'm somewhat stumped at the moment due to problems with inserting > strings in postgresql containing 's. Somewhat offtopic, but you shouldn't have to do this. First hit off Google for Postgres Ruby bindings shows support for bind values, if not prepared statements. So, if you're doing this: questionable_string.gsub!(... #try to escape stuff connection.query "INSERT INTO my_table (some_column) VALUES (#{questionable_string})" Do this instead: connection.query 'INSERT INTO my_table (some_column) VALUES (?)', questionable_string That way, either a library will do the substitution for you, or there's actually going to be some protocol used in the communication with the Postgres server which avoids parsing the bind values as code. My own SQL may be a little rusty, but the concept is the same.