πŸ“š General & Other

Quoting Without Escaping Is an Injection Waiting to Happen

Wrapping values in quotes is only safe if the values cannot contain the quote character. When they can, quoting alone produces broken syntax at best and an injection vector at worst.

Wrapping values in quotes is only safe if the values cannot contain the quote character. When they can, quoting alone produces broken syntax at best and an injection vector at worst.

The escape rules differ per format

SQL escapes a single quote by doubling it. JSON escapes with a backslash, and also requires escaping backslashes, control characters and certain Unicode ranges. CSV doubles the quote. Applying one format's rule to another produces output that parses incorrectly or not at all.

Never build queries by string concatenation

A quoted list pasted into a query is fine for a one-off exploration by a human who can see the data. In application code, use parameterised queries β€” the parameter binding handles escaping correctly for every value, which no amount of manual quoting reliably does.

Serialise rather than assemble

For JSON, use the language's serialiser on an array rather than constructing the literal by wrapping and joining. It handles every escape case, including the ones you have not thought of, and costs one line.

Try it: Wrap Lines in Quotes on SeoWolf's Notepad.