When you think ASP, think...
Recent Articles
All Articles
ASP.NET Articles
ASPFAQs.com
Message Board
Related Web Technologies
User Tips!
Coding Tips

Sections:
Sample Chapters
Commonly Asked Message Board Questions
JavaScript Tutorials
MSDN Communities Hub
Official Docs
Security
Stump the SQL Guru!
XML Info
Information:
Feedback
Author an Article
ASP ASP.NET ASP FAQs Message Board Feedback

The 4 Guys Present: ASPFAQs.com

Jump to a FAQ
Enter FAQ #:
..or see our 10 Most Viewed FAQs.

4GuysFromRolla.com : ASP FAQS : Databases, Queries


Question:

How do I get SQL to accept an apostrophe in various queries, such as when I try to add a user named "O'Brien"?


[Print this FAQ]

Answer: Just as VBScript uses a pair of " marks inside a literal string to represent a single embedded ", so does SQL use a pair of ' marks within a literal to mean a single embedded '.

That is, with VBScript you can do:

<%
  demoText = "He said, ""This should work!"" "
  Response.Write demoText
%>

and the line
    He said, "This should work"
will appear in the browser.

So with SQL, you do something similar:

<%
  SQL = "INSERT INTO table (userName) VALUES('O''Brien')"
  someConnection.Execute SQL
%>

That will insert the name O'Brien into the database.

What do you do when you get a value from a FORM input and need to check for an embedded apostrophe? Use the VBScript REPLACE function.

Thus:

<%
  valueForSQL = Replace( Request.Form("userName"), "'", "''" )
  SQL = "INSERT INTO table (userName) VALUES(" & valueForSQL & ")"
  someConnection.Execute SQL
%>

If the strings used in that REPLACE are hard to read, you could do this, instead:

<%
  SQLQT = Chr(39) ' this is the apostrophe character!
  ...
  valueForSQL = Replace( Request.Form("userName"), SQLQT, SQLQT & SQLQT )
  ...
%>

And that makes it pretty clear that you are replacing a single apostrophe with a pair of them.

Zach Mattson offers a nifty function to automatically replace all instances of single apostrophes with double apostrophes in the Request.Form collection!

I use a function that takes the entire form collection and stuffs it into another collection (a Dictionary object) but, as it moves the contents from the Request.Form collection over to the Dictionary object, it replaces all single apostrophes with double apostrophes.

<%
'*********************************************************
Function RemoveCharacters()
  dim frm,item
  Set frm = Server.CreateObject("Scripting.Dictionary")
  frm.CompareMode=1
  For each Item in Request.Form
    frm.Add Cstr(Item), Replace(Request.Form(Item),"'","''")
  Next
  Set RemoveCharacters = frm
End Function
'*************************************************
%>

Calling and using this function is a breeze:

<%
  dim myform
  Set myform = RemoveCharacters()

  myform("formfieldname") ' refer to a specific form field
%>

Big Thanks To Bill Wilkinson for his help on that one!


FAQ posted by Bill Wilkinson at 9/26/2000 4:14:15 PM to the Databases, Queries category. This FAQ has been viewed 79,199 times.

Do you have a FAQ you'd like to suggest? Suggestions? Comments? If so, send it in! Also, if you'd like to be a FAQ Admin (creating/editing FAQs), let me know! If you are looking for other FAQs, be sure to check out the 4Guys FAQ and Commonly Asked Messageboard Questions!

Most Viewed FAQs:

1.) How can I format numbers and date/times using ASP.NET? For example, I want to format a number as a currency. (761643 views)
2.) I am using Access and getting a 80004005 error (or a [Microsoft][ODBC Microsoft Access Driver] The Microsoft Jet database engine cannot open the file '(unknown)' error) when trying to open a connection! How can I fix this problem? (207777 views)
3.) How can I convert a Recordset into an array? Also, how can I convert an array into a Recordset? (202549 views)
4.) How can I quickly sort a VBScript array? (196039 views)
5.) How can I find out if a record already exists in a database? If it doesn't, I want to add it. (156019 views)
6.) How do I display data on a web page using arrays instead of Do...While...MoveNext...???... (152331 views)
7.) When I get a list of all files in a directory via the FileSystemObject, they aren't ordered in any reasonable way. How can I sort the files by name? Or by size? Or by date created? Or... (140381 views)
8.) For session variables to work, must the Web visitor have cookies enabled? (110162 views)
9.) Can I send emails without using CDONTS? (107083 views)
10.) How can I take the result of a SELECT...MULTIPLE or a group of same-named checkboxes and turn it into a query? That is, if the user selects 3 answers, how can I construct a query that looks for all 3? (106308 views)
Last computed at 9/17/2007 3:22:00 AM


ASP.NET [1.x] [2.0] | ASPMessageboard.com | ASPFAQs.com | Advertise | Feedback | Author an Article