From 077a801df0fa3dcb940ac1fdfe6d95e5f3b98e69 Mon Sep 17 00:00:00 2001 From: Ted Trask Date: Fri, 8 Feb 2013 20:31:00 +0000 Subject: Use luasql to escape, rather than doing it ourselves, because will account for database settings --- provisioning-model.lua | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/provisioning-model.lua b/provisioning-model.lua index ca04d36..c4b718d 100644 --- a/provisioning-model.lua +++ b/provisioning-model.lua @@ -47,7 +47,7 @@ end -- Escape special characters in sql statements local escape = function(sql) sql = sql or "" - return string.gsub(sql, "'", "''") + return con:escape(sql) end local createdatabase = function() -- cgit v1.2.3