Great Ideas. Always Flowing.

We are not happy until you are happy. Client satisfaction guaranteed. Whatever your needs and requirements, we have the skills and resources for the job!

Quick login...


Or... now make it easy with Facebook Integration
Connect via Facebook



Top Sellers

Frustrated over the lack of customization for your user's registration fields? Dynamically setup your DNN Portal with custom registration fields, layout, questions, and other core integration options......

Ultra Video Gallery is a brother product of Ultra Media Gallery, UVG allows you to upload videos in various format and automatically encode them to flv or H264 format, you also can add videos from internet or record live videos from your webcam.

Build high performance, completely customizable data-entry forms and views driven by your DNN and external databases. New built-in tools make it a snap to quickly create data entry forms, data views, and even database tables. Plus, add your own HTML, CSS, Javascript, SQL commands, stored procedures,

The most advanced DotNetNuke shopping cart on the planet. Easy to use e-Commerce, Secure Shopping Cart Software and SEO friendly. B2C / B2B Ecommerce Sites.

One stop solution for events calendar and events registration! FREE DOWNLOAD is available now!

Rich Text Editor data being wrapped in tripple hash tags when word contains SQL syntax
Last Post 01-22-2013 05:01 AM by Ryan Bakerink. 1 Replies.
AddThis - Bookmarking and Sharing Button Printer Friendly
  •  
  •  
  •  
  •  
  •  
Sort:
PrevPrev NextNext
You are not authorized to post a reply.
Author Messages
concentriumUser is Offline
skipping stones
skipping stones
Posts:9
Avatar

--
01-21-2013 06:10 PM
    Have a form that has a completion event that calls a stored procedure and passes in the contents of Rich Text Editor field.  This is a description field for an event for example.

    If the user enters text that contains a word that also happens to be SQL syntax like Count, Select, Join the word gets wrapped in 2 sets of tripple hash tags.  So if the user enters something like "Join us for this great webinar..." what get's stored in the DB is:
    "###Join### us for this great webinar..."


    Sorry if this has been asked before.  I searched for 20 minutes and only thing similar I found is people having issues with single quote messing up their SP call.
    Ryan BakerinkUser is Offline
    river guide
    river guide
    Posts:1900
    Avatar

    --
    01-22-2013 05:01 AM
    Hello,

    To handle the INSERTED "#" marks into your Rich Editor Token, I would recommend passing this as the parameter to your Stored Procedure for your Rich Editor provided value:

    replace('$(TextEditorShortName)', '#', '')

    This SQL Statement will replace any found instances of '#' with ''.


    It's true that a Single Quote can interfere with your stored procedure calls. So it may be important to replace or escape certain characters that can break your SQL Procedure call.

    Take a look at this thread, they discuss how to escape a single quote:
    http://stackoverflow.com/questions/...sql-server

    Another method may be to use SQL to replace single quotes with an HTML ASCII code of "'". This way you're storing this HTML code instead of the real single quote. You can always convert ' back to a single quote. You can learn about other ASCII Codes from here:
    http://www.ascii.cl/htmlcodes.htm

    Please let me know if you have any questions.

    Thanks,

    Ryan

    You are not authorized to post a reply.


     
     

    Join our mailing list...

    Get current news and events the easy way
    Subscribe Me

    Recent Blogs...

     
    Copyright 2005 - 2011 by Data Springs, Inc.
     
  • film izle
  • 720 izle
  • film
  • sinema izle
  • film makinesi
  • T�rk�e dublaj film
  • film izle
  • film izle
  • baglan film izle
  • sinema izle
  • 1080 film izle
  • film mercegi