I’m parsing a xml file and inserting it into database.
However since some text containes double or single quotation I’m having problem with insertion. Currently I’m using the code shown below. But it seems it’s inefficient.
s = s.replace('"', ' ')
s = s.replace("'", ' ')
Is there any way I can insert text without replacing these quotations?
OR
Is there any efficient way to substitute them efficiently ?
Thanks !
Why can’t you insert strings containing quote marks into your database? Is there some weird data type that permits any character except a quote mark? Or are you building an
insertstatement with literal strings, rather than binding your strings to query parameters as you should be doing?If you’re doing
then that’s unsafe and wrong. Instead, you should be doing