parent
77df02313d
commit
c16ee37a71
1 changed files with 17 additions and 3 deletions
|
|
@ -118,10 +118,24 @@ when false:
|
||||||
|
|
||||||
proc dbQuote*(s: string): string =
|
proc dbQuote*(s: string): string =
|
||||||
## DB quotes the string.
|
## DB quotes the string.
|
||||||
result = "'"
|
result = newStringOfCap(s.len + 2)
|
||||||
|
result.add "'"
|
||||||
for c in items(s):
|
for c in items(s):
|
||||||
if c == '\'': add(result, "''")
|
# see https://cheatsheetseries.owasp.org/cheatsheets/SQL_Injection_Prevention_Cheat_Sheet.html#mysql-escaping
|
||||||
else: add(result, c)
|
case c
|
||||||
|
of '\0': result.add "\\0"
|
||||||
|
of '\b': result.add "\\b"
|
||||||
|
of '\t': result.add "\\t"
|
||||||
|
of '\l': result.add "\\n"
|
||||||
|
of '\r': result.add "\\r"
|
||||||
|
of '\x1a': result.add "\\Z"
|
||||||
|
of '"': result.add "\\\""
|
||||||
|
of '%': result.add "\\%"
|
||||||
|
of '\'': result.add "\\'"
|
||||||
|
of '\\': result.add "\\\\"
|
||||||
|
of '_': result.add "\\_"
|
||||||
|
of Letters+Digits: result.add c
|
||||||
|
else: result.add "\\" & $ord(c)
|
||||||
add(result, '\'')
|
add(result, '\'')
|
||||||
|
|
||||||
proc dbFormat(formatstr: SqlQuery, args: varargs[string]): string =
|
proc dbFormat(formatstr: SqlQuery, args: varargs[string]): string =
|
||||||
|
|
|
||||||
Loading…
Add table
Add a link
Reference in a new issue