From: Brian Candler Date: 2003-08-29T23:37:57+09:00 Subject: Re: Quoted string problem On Fri, Aug 29, 2003 at 11:28:28PM +0900, Meino Christian Cramer wrote: > There is one filed called "comment" in the database, where ANYTHING > printable can be exspected. > > One line says has a comment like > > International service "A". > > At this point, mysqld jumps from the rail and says "STOP! SYNTAX > VIOLATED". > > Generally: how can I process input to escape "special" characters > before I send them to mysqld? With DBI it would be something like this: @dbh.do("insert into mydb (station,comment) values (?,?)", stationid, comment) i.e. use "?" as a placeholder and then bind a variable to it. There is also a 'quote' method of the database handle you can use. > (In perl there is a command called "quotemeta", which does the > thing...I found nothing equivalent in the docs for ruby). This article talks about it: http://www.kitebird.com/articles/ruby-dbi.html See section entitled "Quoting, Placeholders, and Parameter Binding" Regards, Brian.