[Templates] Re: templates digest, Vol 1 #678 - 1 msg

Mark Mills mark@xodiax.com
Fri, 20 Sep 2002 13:23:11 -0400


> When I post content I use an editor from sourceforge and part=20
> of the post
> includes "'s that are in html. As soon as the variable is put into the

Read up on $dbi->quote();

There is a nice, builtin way for your SQL server to escape quotes.

(The trick, commonly, in SQL is this: "blah ""in quotes"" blah")

In the old days you did s/"/""/g; but nowadays you're better off letting
DBI take care of it...

--mark