Properly handle backslash escaping

This commit is contained in:
Loic Nageleisen 2017-11-23 16:33:01 +01:00
parent a0f1153407
commit 86ce2b65ff
2 changed files with 25 additions and 11 deletions

View file

@ -292,7 +292,10 @@ module Rebel
end
def escape_str(str)
str.gsub(@string_quote, @escaped_string_quote)
str.dup.tap do |s|
s.gsub!('\\') { @escaped_string_backslash } if @escaped_string_backslash
s.gsub!(@string_quote) { @escaped_string_quote }
end
end
def value(v)
@ -390,6 +393,7 @@ module Rebel
@identifier_quote = options[:identifier_quote] || '"'
@string_quote = options[:string_quote] || "'"
@escaped_string_quote = options[:escaped_string_quote] || "''"
@escaped_string_backslash = options[:escaped_string_backslash]
@true_literal = options[:true_literal] || 'TRUE'
@false_literal = options[:false_literal] || 'FALSE'

View file

@ -8,7 +8,7 @@ class TestRaw < Minitest::Test
end
def assert_mysql(expected, &actual)
assert_equal(expected.to_s, Rebel::SQL(identifier_quote: '`', string_quote: '"', escaped_string_quote: '""', &actual).to_s)
assert_equal(expected.to_s, Rebel::SQL(identifier_quote: '`', escaped_string_quote: "\\'", escaped_string_backslash: '\\', &actual).to_s)
end
def assert_sqlite(expected, &actual)
@ -137,21 +137,31 @@ class TestRaw < Minitest::Test
def test_string
assert_sql("'FOO'") { value('FOO') }
assert_mysql('"FOO"') { value('FOO') }
assert_mysql("'FOO'") { value('FOO') }
assert_postgresql("'FOO'") { value('FOO') }
assert_sqlite("'FOO'") { value('FOO') }
end
def test_escaped_string
assert_sql("'FOO''BAR'") { value("FOO'BAR") }
assert_mysql('"FOO\'BAR"') { value("FOO'BAR") }
assert_postgresql("'FOO''BAR'") { value("FOO'BAR") }
assert_sqlite("'FOO''BAR'") { value("FOO'BAR") }
assert_sql (%q('FOO''BAR')) { value(%q(FOO'BAR)) }
assert_postgresql (%q('FOO''BAR')) { value(%q(FOO'BAR)) }
assert_sqlite (%q('FOO''BAR')) { value(%q(FOO'BAR)) }
assert_mysql (%q('FOO\'BAR')) { value(%q(FOO'BAR)) }
assert_sql("'FOO\"BAR'") { value('FOO"BAR') }
assert_mysql('"FOO""BAR"') { value('FOO"BAR') }
assert_postgresql("'FOO\"BAR'") { value('FOO"BAR') }
assert_sqlite("'FOO\"BAR'") { value('FOO"BAR') }
assert_sql (%q('FOO"BAR')) { value(%q(FOO"BAR)) }
assert_postgresql (%q('FOO"BAR')) { value(%q(FOO"BAR)) }
assert_sqlite (%q('FOO"BAR')) { value(%q(FOO"BAR)) }
assert_mysql (%q('FOO"BAR')) { value(%q(FOO"BAR)) }
assert_sql (%q('FOO\BAR')) { value(%q(FOO\BAR)) }
assert_postgresql (%q('FOO\BAR')) { value(%q(FOO\BAR)) }
assert_sqlite (%q('FOO\BAR')) { value(%q(FOO\BAR)) }
assert_mysql (%q('FOO\\BAR')) { value(%q(FOO\BAR)) }
assert_sql (%q('FOO\\''BAR')) { value(%q(FOO\'BAR)) }
assert_postgresql (%q('FOO\\''BAR')) { value(%q(FOO\'BAR)) }
assert_sqlite (%q('FOO\\''BAR')) { value(%q(FOO\'BAR)) }
assert_mysql (%q('FOO\\\'BAR')) { value(%q(FOO\'BAR)) }
end
def test_boolean_literal