* fixes #20153; do not escape `_` for mysql * add a test * Update db_mysql.nim * Update tdb_mysql.nim Co-authored-by: Clay Sweetser <Varriount@users.noreply.github.com>
This commit is contained in:
parent
3fef2fd52c
commit
3bd935f331
2 changed files with 5 additions and 2 deletions
|
|
@ -117,7 +117,7 @@ when false:
|
||||||
discard mysql_stmt_close(stmt)
|
discard mysql_stmt_close(stmt)
|
||||||
|
|
||||||
proc dbQuote*(s: string): string =
|
proc dbQuote*(s: string): string =
|
||||||
## DB quotes the string.
|
## DB quotes the string. Note that this doesn't escape `%` and `_`.
|
||||||
result = newStringOfCap(s.len + 2)
|
result = newStringOfCap(s.len + 2)
|
||||||
result.add "'"
|
result.add "'"
|
||||||
for c in items(s):
|
for c in items(s):
|
||||||
|
|
@ -132,7 +132,6 @@ proc dbQuote*(s: string): string =
|
||||||
of '"': result.add "\\\""
|
of '"': result.add "\\\""
|
||||||
of '\'': result.add "\\'"
|
of '\'': result.add "\\'"
|
||||||
of '\\': result.add "\\\\"
|
of '\\': result.add "\\\\"
|
||||||
of '_': result.add "\\_"
|
|
||||||
else: result.add c
|
else: result.add c
|
||||||
add(result, '\'')
|
add(result, '\'')
|
||||||
|
|
||||||
|
|
|
||||||
4
tests/stdlib/tdb_mysql.nim
Normal file
4
tests/stdlib/tdb_mysql.nim
Normal file
|
|
@ -0,0 +1,4 @@
|
||||||
|
import std/db_mysql
|
||||||
|
|
||||||
|
doAssert dbQuote("SELECT * FROM foo WHERE col1 = 'bar_baz'") == "'SELECT * FROM foo WHERE col1 = \\'bar_baz\\''"
|
||||||
|
doAssert dbQuote("SELECT * FROM foo WHERE col1 LIKE '%bar_baz%'") == "'SELECT * FROM foo WHERE col1 LIKE \\'%bar_baz%\\''"
|
||||||
Loading…
Add table
Add a link
Reference in a new issue