Hello everybody, I would like to ask you if it is safe to use the LIKE
clause as follow:

Artilce.find(:all, :conditions => ["title LIKE ?", '%' +  params[:title]
+'%'])

Is it safe for sql iyection ? or do I need to escape all characters ???

Thanks in advance

--

You received this message because you are subscribed to the Google Groups "Ruby 
on Rails: Talk" group.
To post to this group, send email to [email protected].
To unsubscribe from this group, send email to 
[email protected].
For more options, visit this group at 
http://groups.google.com/group/rubyonrails-talk?hl=en.


Reply via email to