Re: don't understand something about backslashes - Mailing list pgsql-general

From Stephan Szabo
Subject Re: don't understand something about backslashes
Date
Msg-id 20030320115548.D73004-100000@megazone23.bigpanda.com
Whole thread Raw
In response to don't understand something about backslashes  (Dennis Gearon <gearond@cvc.net>)
Responses Re: don't understand something about backslashes  (Dennis Gearon <gearond@cvc.net>)
List pgsql-general
On Thu, 20 Mar 2003, Dennis Gearon wrote:

> I have a varchar that is 64 wide. I prescape stuff like the '-'
> character to prevent SQL injection.
>
> Here is the EXACT field value that I inserted recently,for a test. It
> comes to approx 100 chars.
>
> '\-1\-1\-1\-1\-1\-1\-1\-1\-1\-1\-1\-1\-1\-1\-1\-1\-1\-1\-1\-1\-1\-1\-1\-1\-1\-1\-1\-1\-1\-1\-1\-1'::varchar,
>
> I insert that and get:
>
>     NO ERROR
>
> When I look at the record in phpPgAdmin, the slashes don't show up in
> the record.

The backslashes are escaping what follows.  If you want two backslashes
you need to double them probably.


pgsql-general by date:

Previous
From: Andrew Sullivan
Date:
Subject: Re: log_timestamp and SIGHUP?
Next
From: Dennis Gearon
Date:
Subject: Re: don't understand something about backslashes