I want/need to escape underscores so that simple searches can't be 
"hacked" by users, accidentally or intentionally. The DBI doc shows 
this as the way to do it:

   $esc = $dbh->get_info( 14 );  # SQL_SEARCH_PATTERN_ESCAPE
   $search_pattern =~ s/([_%])/$esc$1/g;

Where/how should I do it in (a Catalyst app that's doing) searches with 
DBIC? I'm interested in overriding it for *all* user facing searches 
since users should only be allowed to supply literal chars.

Thanks!


-Ashley
-- 


_______________________________________________
List: http://lists.rawmode.org/cgi-bin/mailman/listinfo/dbix-class
Wiki: http://dbix-class.shadowcatsystems.co.uk/
IRC: irc.perl.org#dbix-class
SVN: http://dev.catalyst.perl.org/repos/bast/trunk/DBIx-Class/
Searchable Archive: http://www.mail-archive.com/[email protected]/

Reply via email to