Ruby on Rails
Monday, December 23, 2013
On 2013-Dec-24, at 01:45 , Daynthan Kabilan <dayanthan86@gmail.com> wrote:
Hi all,how to avoid single quote in our rails searchExamplein my users table user_name=ram'kumarmy search queryparams[:name]=ramkumar@ans=Users.where("user_name=?",params[:name])
@ans = User.where(user_name: params[:name])
and let the ActiveRecord gem sanitize the parameters
If you're not using the latest version of Rails, you'll need to give more specifics before you can get better help.
-Rob
how can i get the value?any one give me a solutionThankyou.--
You received this message because you are subscribed to the Google Groups "Ruby on Rails: Talk" group.
To unsubscribe from this group and stop receiving emails from it, send an email to rubyonrails-talk+unsubscribe@googlegroups.com.
To post to this group, send email to rubyonrails-talk@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/rubyonrails-talk/CADKeJyRuuoBPCvs3-5MP8PJQLrLBWrdCVhPoj4K9UeSC9fxj5Q%40mail.gmail.com.
For more options, visit https://groups.google.com/groups/opt_out.
Subscribe to:
Post Comments (Atom)
No comments:
Post a Comment