Solved

Apostrophe in WHERE clause in a dynamic SQL statement

Posted on 2004-09-07
2
1,646 Views
Last Modified: 2011-10-03
Could anyone help me with the following apostrophe problem with MS SQL Server 2000? I searched this site but couldn't find a good solution. Some answers are about the INSERT or UPDATE part of the SQL statement, NOT the WHERE part as what I need.

NOTE: The following is used in a SP on the server, NOT via a Front End.

I have a dynamic SQL statement to update data in tables, but it will fail whenever the field 'Customer_Name' contains an apostrophe in the WHERE part.

Here are some details:

-- some code omitted, including variables....

-- Update 'Sales_Total' in Table '@vchDataSource (this table name is dynamic, such as 'tblSales_Summary').
-- On this particular occasion, Customer_Name (@vchCustomerName ) is unique but may contain apostrophe(s), which will casue a problem.

SELECT @vchSQL ='UPDATE ' + @vchDataSource +
                              '  SET Sales_Total= ' + CONVERT(VARCHAR, @mnySales_Total_ByCustomer) +
                              ',  Last_Update = '''  + CONVERT(VARCHAR, @dtmCurrentDate)  +
                     '''  WHERE Customer_Name = ''' +   @vchCustomerName + ''''

EXEC (@vchSQL)



0
Comment
Question by:Yongshu Li
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
2 Comments
 
LVL 18

Expert Comment

by:SjoerdVerweij
ID: 12000893
SELECT @vchSQL ='UPDATE ' + @vchDataSource +
                              '  SET Sales_Total= ' + CONVERT(VARCHAR, @mnySales_Total_ByCustomer) +
                              ',  Last_Update = '''  + CONVERT(VARCHAR, @dtmCurrentDate)  +
                    '''  WHERE Customer_Name = ''' +   replace(@vchCustomerName,  '''', '''''') + ''''

Note that the second parameter to Replace is 4 single quotes; the third 6 single quotes.
0
 
LVL 18

Accepted Solution

by:
SjoerdVerweij earned 500 total points
ID: 12000914
Actually,

SELECT @vchSQL ='UPDATE ' + @vchDataSource +
                              '  SET Sales_Total= ' + CONVERT(VARCHAR, @mnySales_Total_ByCustomer) +
                              ',  Last_Update = '''  + CONVERT(VARCHAR, @dtmCurrentDate)  +
                    '  WHERE Customer_Name = ''' +   replace(@vchCustomerName,  '''', '''''') + ''''
0

Featured Post

What is SQL Server and how does it work?

The purpose of this paper is to provide you background on SQL Server. It’s your self-study guide for learning fundamentals. It includes both the history of SQL and its technical basics. Concepts and definitions will form the solid foundation of your future DBA expertise.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
CRM Online Report - Passing Parameter from Opportunity to Report 1 44
Access Report formatting issue 5 64
mysql vs miscrosoft sql server 6 52
dat and idx extensions 11 38
Never store passwords in plain text or just their hash: it seems a no-brainier, but there are still plenty of people doing that. I present the why and how on this subject, offering my own real life solution that you can implement right away, bringin…
Recently, Microsoft released a best-practice guide for securing Active Directory. It's a whopping 300+ pages long. Those of us tasked with securing our company’s databases and systems would, ideally, have time to devote to learning the ins and outs…
Video by: Steve
Using examples as well as descriptions, step through each of the common simple join types, explaining differences in syntax, differences in expected outputs and showing how the queries run along with the actual outputs based upon a simple set of dem…
Polish reports in Access so they look terrific. Take yourself to another level. Equations, Back Color, Alternate Back Color. Write easy VBA Code. Tighten space to use less pages. Launch report from a menu, considering criteria only when it is filled…

740 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question