Bugs item #1775552, was opened at 2007-08-16 19:38
Message generated for change (Comment added) made by phd
You can respond by visiting:
https://sourceforge.net/tracker/?func=detail&atid=540672&aid=1775552&group_id=74338
Please note that this message will contain a full copy of the comment thread,
including the initial issue submission, for this request,
not just the latest update.
Category: Postgres
Group: SQLObject release (specify)
>Status: Closed
>Resolution: Fixed
Priority: 5
Private: No
Submitted By: fuchsd (fuchsd)
>Assigned to: Oleg Broytmann (phd)
Summary: Escaping Single Quotes in Postgres
Initial Comment:
Using Postgres 8.3, SQLObject-0-8.1, and psycopg2 2.0.5.1, the following code breaks:
from sqlobject import *
sqlhub.processConnection = connectionForURI('<some postgres DSN>')
class Foo(SQLObject):
entry = StringCol()
Foo.createTable()
f = Foo(entry="Here's an entry")
With this error:
psycopg2.ProgrammingError: syntax error at or near "s"
LINE 1: INSERT INTO bar (id, entry) VALUES (1, 'Here\'s an entry')
Our Postgres server does not allow using a backslash to escape single quotes (this could potentially allow a SQL injection attack: http://www.postgresql.org/docs/8.2/static/runtime-config-compatible.html),
it only allows using another single quote (I'm not sure if we configured it to now allow escaping single quotes with backslashes, or if Postgres defaults to this behavior after a certain version).
This escaping is being done in StringLIkeConverter method at line 104 in converters.py .
----------------------------------------------------------------------
>Comment By: Oleg Broytmann (phd)
Date: 2007-08-16 19:51
Message:
Logged In: YES
user_id=4799
Originator: NO
This was fixed in SQLObject 0.7.8, 0.8.5 and 0.9.1. See
http://sqlobject.org/News.html#sqlobject-0-7-8
----------------------------------------------------------------------
You can respond by visiting:
https://sourceforge.net/tracker/?func=detail&atid=540672&aid=1775552&group_id=74338
|