阅读背景:

Ruby on Rails:如何在不使用find时清理SQL的字符串?

来源:互联网 

I'm trying to sanitize a string that involves user input without having to resort to manually crafting my own possibly buggy regex if possible, however, if that is the only way I would also appreciate if anyone can point me in the right direction to a regex that is unlikely to be missing anything. There are a number of methods in Rails that can allow you to enter in native SQL commands, how do people escape user input for those? I'm trying to sanitize a string that involves u




你的当前访问异常,请进行认证后继续阅读剩余内容。

分享到: