fixes #20153; do not escape _ for mysql [backport] (#20164)

* fixes #20153; do not escape `_` for mysql

* add a test

* Update db_mysql.nim

* Update tdb_mysql.nim

Co-authored-by: Clay Sweetser <Varriount@users.noreply.github.com>
This commit is contained in:
ringabout 2022-08-06 05:15:58 +08:00 • committed by GitHub
commit 3bd935f331
No known key found for this signature in database
GPG key ID: 4AEE18F83AFDEB23
2 changed files with 5 additions and 2 deletions

View file

@ -117,7 +117,7 @@ when false:
discard mysql_stmt_close(stmt) discard mysql_stmt_close(stmt)
proc dbQuote*(s: string): string = proc dbQuote*(s: string): string =
## DB quotes the string. ## DB quotes the string. Note that this doesn't escape `%` and `_`.
result = newStringOfCap(s.len + 2) result = newStringOfCap(s.len + 2)
result.add "'" result.add "'"
for c in items(s): for c in items(s):
@ -132,7 +132,6 @@ proc dbQuote*(s: string): string =
of '"': result.add "\\\"" of '"': result.add "\\\""
of '\'': result.add "\\'" of '\'': result.add "\\'"
of '\\': result.add "\\\\" of '\\': result.add "\\\\"
of '_': result.add "\\_"
else: result.add c else: result.add c
add(result, '\'') add(result, '\'')

View file

@ -0,0 +1,4 @@
import std/db_mysql
doAssert dbQuote("SELECT * FROM foo WHERE col1 = 'bar_baz'") == "'SELECT * FROM foo WHERE col1 = \\'bar_baz\\''"
doAssert dbQuote("SELECT * FROM foo WHERE col1 LIKE '%bar_baz%'") == "'SELECT * FROM foo WHERE col1 LIKE \\'%bar_baz%\\''"