T-SQL escape quote character

前端 未结 1 1803
时光取名叫无心
时光取名叫无心 2020-12-11 15:10

NOTE: It\'s probably a duplicate but I can\'t find working answer.

Following is what i\'m trying todo, notice a \' in the value. How do I fix this?

相关标签:
1条回答
  • 2020-12-11 15:40

    This will work:-

    INSERT INTO [pugraider].[dbo].[Realms]([Name]) VALUES('Aman''Thul')
    

    Ordinarily the only reason to have such hardcoded values in T-SQL is in DB construction code such as initialising look up tables.

    Otherwise this code might be a result of string concatenation to build up some T-SQL from some input source. If that is the case its worth finding ways to avoid it since it can open your application to SQL injection attacks.

    0 讨论(0)
提交回复
热议问题