A good way to escape quotes in a database query string?

后端 未结 9 1244
暖寄归人
暖寄归人 2020-12-09 07:49

I\'ve tried all manner of Python modules and they either escape too much or in the wrong way. What\'s the best way you\'ve found to escape quotes (\", \') in Python?

9条回答
  •  隐瞒了意图╮
    2020-12-09 08:27

    If it's part of a Database query you should be able to use a Parameterized SQL Statement.

    As well as escaping your quotes, this will deal with all special characters and will protect you from SQL injection attacks.

提交回复
热议问题