I just committed on the cvs an updated to unixodbc which escapes single quotes, backslashes and NULL characters. Could you give it a try and let me know if works? Long term solution would be to use prepare statements APIs -- needs more investigation.

Cheers,
Daniel


On 01/12/07 13:16, Jerome Martin wrote:
On Thu, 2007-01-11 at 17:43 +0100, Klaus Darilion wrote:
Jerome Martin wrote:
Hello Klaus,

Thanks for at least replying to my email, I feel a bit less lonely ;-)

If I got the picture right, I'm encouraged to submit changes and
investigate myself for the other issues. Well, I guess I'll have to get
This is how it is solved fastest as we all are busy. I have checked the unixodbc API but could not find any function which escaped the values :-(

Yes, I came to the same conclusion, I could'nt find anything like that
either.

Probably it must be done by manually.

I'm going to try and reap some code from an other DB API library.
Probably generic SQL escaping is good enough.

regards
klaus


myself closer to the sources so I can contribute patches and trace down
the crashes. Will do. I just hope I can make it for 1.2. According to
the roadmap, it's due by the end of winter. Is that still the plan ? Do
you have a timeframe before hard codebase freeze ?

Best Regards,
Jérôme Martin



_______________________________________________
Devel mailing list
Devel@openser.org
http://openser.org/cgi-bin/mailman/listinfo/devel


_______________________________________________
Devel mailing list
Devel@openser.org
http://openser.org/cgi-bin/mailman/listinfo/devel

Reply via email to