Bugs item #1775552, was opened at 2007-08-16 10:38
Message generated for change (Tracker Item Submitted) made by Item Submitter
You can respond by visiting:
https://sourceforge.net/tracker/?func=detail&atid=540672&aid=1775552&group_id=74338
Please note that this message will contain a full copy of the comment thread,
including the initial issue submission, for this request,
not just the latest update.
Category: Postgres
Group: SQLObject release (specify)
Status: Open
Resolution: None
Priority: 5
Private: No
Submitted By: fuchsd (fuchsd)
Assigned to: Nobody/Anonymous (nobody)
Summary: Escaping Single Quotes
Initial Comment:
Using Postgres 8.3, SQLObject-0-8.1, and psycopg2 2.0.5.1, the following code breaks:
from sqlobject import *
sqlhub.processConnection = connectionForURI('<some postgres DSN>')
class Foo(SQLObject):
entry = StringCol()
Foo.createTable()
f = Foo(entry="Here's an entry")
With this error:
psycopg2.ProgrammingError: syntax error at or near "s"
LINE 1: INSERT INTO bar (id, entry) VALUES (1, 'Here\'s an entry')
Our Postgres server does not allow using a backslash to escape single quotes (this could potentially allow a SQL injection attack: http://www.postgresql.org/docs/8.2/static/runtime-config-compatible.html),
it only allows using another single quote (I'm not sure if we configured it to now allow escaping single quotes with backslashes, or if Postgres defaults to this behavior after a certain version).
This escaping is being done in StringLIkeConverter method at line 104 in converters.py .
----------------------------------------------------------------------
You can respond by visiting:
https://sourceforge.net/tracker/?func=detail&atid=540672&aid=1775552&group_id=74338
|