Mailing Lists: Apple Mailing Lists

Image of Mac OS face in stamp
 
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: preventing sql injection



This one will not work, because % and * are part of the regular _expression_ syntax/ 

This however, did work:   filterString = filterString.replaceAll("[\\*\\%\\?]","");
Character classes in regexs do not actually require escaping, so filterString.replaceAll("[*%?]","") would be what you actually want ... Otherwise I would expect you're probably inadvertently removing backslashes also.

ms
 _______________________________________________
Do not post admin requests to the list. They will be ignored.
Webobjects-dev mailing list      (email@hidden)
Help/Unsubscribe/Update your Subscription:
http://lists.apple.com/mailman/options/webobjects-dev/email@hidden

This email sent to email@hidden

References: 
 >preventing sql injection (From: Johan Henselmans <email@hidden>)
 >Re: preventing sql injection (From: Q <email@hidden>)
 >Re: preventing sql injection (From: Johan Henselmans <email@hidden>)
 >Re: preventing sql injection (From: "John Huss" <email@hidden>)
 >Re: preventing sql injection (From: Johan Henselmans <email@hidden>)



Visit the Apple Store online or at retail locations.
1-800-MY-APPLE

Contact Apple | Terms of Use | Privacy Policy

Copyright © 2007 Apple Inc. All rights reserved.