What's wrong with this code?
strLongDesc =
Replace(Replace(Replace(Replace(Trim(Request.Form( "LongDesc")),"'","''"),vbC
rLf,"<br>"),"<",<),"<",>)
Background:
This field is a textarea, and I needed to account for apostrophes, which I
had already done, and replaced line breaks with html line breaks on my page
which displays this stuff. That works fine. But then a user entered this
line, pasted from a log file:
SQL Statement: <SELECT * FROM etc., etc.
Which resulted in an actual dropdown box being displayed, and all the rest
of the description after that point was not displayed. So I tried to put in
code to replace the < and > with a < and > and the code I get when the
page loads is:
Microsoft VBScript compilation (0x800A03EA)
Syntax error
/AddToTicket.asp, line 75, column 106
strLongDesc =
Replace(Replace(Replace(Replace(Trim(Request.Form( "LongDesc")),"'","''"),vbC
rLf,"<br>"),"<",<),"<",>)
----------------------------------------------------------------------------
-----------------------------^ 8 4489
Well, I found the problem with the syntax, but now it simply doesn't work.
Here is my code:
strLongDesc =
Replace(Replace(Replace(Replace(Trim(Request.Form( "LongDesc")),"'","''"),vbC
rLf,"<br>"),"<","<"),">",">")
and of course, I insert strLongDesc into a field in SQL Server, and when I
open it up in SQL Server, it still shows what I typed into the textarea,
which is <select>, whereas I should see <select>
What am I doing wrong?
"middletree" <mi********@htomail.com> wrote in message
news:Oc**************@TK2MSFTNGP11.phx.gbl... What's wrong with this code?
strLongDesc =
Replace(Replace(Replace(Replace(Trim(Request.Form( "LongDesc")),"'","''"),vbC rLf,"<br>"),"<",<),"<",>)
Background: This field is a textarea, and I needed to account for apostrophes, which I had already done, and replaced line breaks with html line breaks on my
page which displays this stuff. That works fine. But then a user entered this line, pasted from a log file: SQL Statement: <SELECT * FROM etc., etc.
Which resulted in an actual dropdown box being displayed, and all the rest of the description after that point was not displayed. So I tried to put
in code to replace the < and > with a < and > and the code I get when
the page loads is:
Microsoft VBScript compilation (0x800A03EA) Syntax error /AddToTicket.asp, line 75, column 106 strLongDesc =
Replace(Replace(Replace(Replace(Trim(Request.Form( "LongDesc")),"'","''"),vbC rLf,"<br>"),"<",<),"<",>) --------------------------------------------------------------------------
-- -----------------------------^
(a) you need double quotes around "<" and ">"
(b) how about :
strLongDesc = trim(server.HTMLEncode(Request.Form("LongDesc")))
strLongDesc = replace(replace(strLongDesc,"'","''"),VBCrLf,"<br> ")
"middletree" <mi********@htomail.com> wrote in message
news:Oc**************@TK2MSFTNGP11.phx.gbl... What's wrong with this code?
strLongDesc =
Replace(Replace(Replace(Replace(Trim(Request.Form( "LongDesc")),"'","''"),vbC rLf,"<br>"),"<",<),"<",>)
Background: This field is a textarea, and I needed to account for apostrophes, which I had already done, and replaced line breaks with html line breaks on my
page which displays this stuff. That works fine. But then a user entered this line, pasted from a log file: SQL Statement: <SELECT * FROM etc., etc.
Which resulted in an actual dropdown box being displayed, and all the rest of the description after that point was not displayed. So I tried to put
in code to replace the < and > with a < and > and the code I get when
the page loads is:
Microsoft VBScript compilation (0x800A03EA) Syntax error /AddToTicket.asp, line 75, column 106 strLongDesc =
Replace(Replace(Replace(Replace(Trim(Request.Form( "LongDesc")),"'","''"),vbC rLf,"<br>"),"<",<),"<",>) --------------------------------------------------------------------------
-- -----------------------------^
> when I open it up in SQL Server,
Where in SQL Server? Don't use Enterprise Manager for viewing data (e.g.
Return all rows). It is liable to do all sorts of funky things in order to
present the data to you in a "friendly" way (for some other issues see http://www.aspfaq.com/2455). Run a SELECT query in Query Analyzer. Also,
response.write(sql) to make sure the replacements were done.
Another piece of friendly advice: store the statement as is, and use
Server.HTMLEncode when you *retrieve* and *display* it. HTML formatting has
little use/place inside the database.
OK, I've not gotten familiar with HTMLEncode. That will take care of the <
and other characters, then?
I'll try it out. Thanks, very much.
I also never knew that that you said about Enterprise Mgr vs. Query analyzer
in the other post. thanks
"Aaron Bertrand [MVP]" <aa***@TRASHaspfaq.com> wrote in message
news:eV*************@TK2MSFTNGP10.phx.gbl... (a) you need double quotes around "<" and ">"
(b) how about:
strLongDesc = trim(server.HTMLEncode(Request.Form("LongDesc"))) strLongDesc = replace(replace(strLongDesc,"'","''"),VBCrLf,"<br> ")
"middletree" <mi********@htomail.com> wrote in message news:Oc**************@TK2MSFTNGP11.phx.gbl... What's wrong with this code?
strLongDesc =
Replace(Replace(Replace(Replace(Trim(Request.Form( "LongDesc")),"'","''"),vbC rLf,"<br>"),"<",<),"<",>)
Background: This field is a textarea, and I needed to account for apostrophes, which
I had already done, and replaced line breaks with html line breaks on my page which displays this stuff. That works fine. But then a user entered this line, pasted from a log file: SQL Statement: <SELECT * FROM etc., etc.
Which resulted in an actual dropdown box being displayed, and all the
rest of the description after that point was not displayed. So I tried to put in code to replace the < and > with a < and > and the code I get when the page loads is:
Microsoft VBScript compilation (0x800A03EA) Syntax error /AddToTicket.asp, line 75, column 106 strLongDesc =
Replace(Replace(Replace(Replace(Trim(Request.Form( "LongDesc")),"'","''"),vbC rLf,"<br>"),"<",<),"<",>)
-------------------------------------------------------------------------- -- -----------------------------^
Well, I tried it exactly as you have it in (b) below, and it didn't work.
Also tried it with double quotes around the <, and it still stored my text
of <select> as <select>, which displayed as a dropdown.
"Aaron Bertrand [MVP]" <aa***@TRASHaspfaq.com> wrote in message
news:eV*************@TK2MSFTNGP10.phx.gbl... (a) you need double quotes around "<" and ">"
(b) how about:
strLongDesc = trim(server.HTMLEncode(Request.Form("LongDesc"))) strLongDesc = replace(replace(strLongDesc,"'","''"),VBCrLf,"<br> ")
"middletree" <mi********@htomail.com> wrote in message news:Oc**************@TK2MSFTNGP11.phx.gbl... What's wrong with this code?
strLongDesc =
Replace(Replace(Replace(Replace(Trim(Request.Form( "LongDesc")),"'","''"),vbC rLf,"<br>"),"<",<),"<",>)
Background: This field is a textarea, and I needed to account for apostrophes, which
I had already done, and replaced line breaks with html line breaks on my page which displays this stuff. That works fine. But then a user entered this line, pasted from a log file: SQL Statement: <SELECT * FROM etc., etc.
Which resulted in an actual dropdown box being displayed, and all the
rest of the description after that point was not displayed. So I tried to put in code to replace the < and > with a < and > and the code I get when the page loads is:
Microsoft VBScript compilation (0x800A03EA) Syntax error /AddToTicket.asp, line 75, column 106 strLongDesc =
Replace(Replace(Replace(Replace(Trim(Request.Form( "LongDesc")),"'","''"),vbC rLf,"<br>"),"<",<),"<",>)
-------------------------------------------------------------------------- -- -----------------------------^
"Aaron Bertrand [MVP]" <aa***@TRASHaspfaq.com> wrote in message
news:eg*************@TK2MSFTNGP10.phx.gbl... when I open it up in SQL Server, Where in SQL Server? Don't use Enterprise Manager for viewing data (e.g. Return all rows). It is liable to do all sorts of funky things in order
to present the data to you in a "friendly" way (for some other issues see http://www.aspfaq.com/2455). Run a SELECT query in Query Analyzer. Also, response.write(sql) to make sure the replacements were done.
As it turned out, the Query A vs. Ent Mgr were both displying correctly, but
I will make sure i view the data correctly from now on. But the problem is
that the replace function is not working. I verified this per your
suggestion with the response.write statement. It does just fine with the
<br> and quotes. Very puzzling and frustrating Another piece of friendly advice: store the statement as is, and use Server.HTMLEncode when you *retrieve* and *display* it. HTML formatting
has little use/place inside the database.
Then my guess is there are no < or > characters for replacement? Compare
this to the completed SQL statement:
Response.write(request.form("whatever_the_variable _was"))
"middletree" <mi********@htomail.com> wrote in message
news:#S**************@TK2MSFTNGP10.phx.gbl... "Aaron Bertrand [MVP]" <aa***@TRASHaspfaq.com> wrote in message news:eg*************@TK2MSFTNGP10.phx.gbl... when I open it up in SQL Server, Where in SQL Server? Don't use Enterprise Manager for viewing data
(e.g. Return all rows). It is liable to do all sorts of funky things in order to present the data to you in a "friendly" way (for some other issues see http://www.aspfaq.com/2455). Run a SELECT query in Query Analyzer.
Also, response.write(sql) to make sure the replacements were done.
As it turned out, the Query A vs. Ent Mgr were both displying correctly,
but I will make sure i view the data correctly from now on. But the problem is that the replace function is not working. I verified this per your suggestion with the response.write statement. It does just fine with the <br> and quotes. Very puzzling and frustrating
Another piece of friendly advice: store the statement as is, and use Server.HTMLEncode when you *retrieve* and *display* it. HTML formatting
has little use/place inside the database.
Well, had typed:
<select>
into the textarea, and verified that this is what went in, both by
response.write, and looking into SQL Server.
"Aaron Bertrand [MVP]" <aa***@TRASHaspfaq.com> wrote in message
news:ut**************@TK2MSFTNGP10.phx.gbl... Then my guess is there are no < or > characters for replacement? Compare this to the completed SQL statement:
Response.write(request.form("whatever_the_variable _was"))
"middletree" <mi********@htomail.com> wrote in message news:#S**************@TK2MSFTNGP10.phx.gbl... "Aaron Bertrand [MVP]" <aa***@TRASHaspfaq.com> wrote in message news:eg*************@TK2MSFTNGP10.phx.gbl... > when I open it up in SQL Server,
Where in SQL Server? Don't use Enterprise Manager for viewing data (e.g. Return all rows). It is liable to do all sorts of funky things in
order to present the data to you in a "friendly" way (for some other issues see http://www.aspfaq.com/2455). Run a SELECT query in Query Analyzer. Also, response.write(sql) to make sure the replacements were done.
As it turned out, the Query A vs. Ent Mgr were both displying correctly, but I will make sure i view the data correctly from now on. But the problem
is that the replace function is not working. I verified this per your suggestion with the response.write statement. It does just fine with the <br> and quotes. Very puzzling and frustrating
Another piece of friendly advice: store the statement as is, and use Server.HTMLEncode when you *retrieve* and *display* it. HTML
formatting has little use/place inside the database.
This thread has been closed and replies have been disabled. Please start a new discussion. Similar topics
by: shank |
last post by:
1) I'm getting this error: Syntax error (missing operator) in query
expression on the below statement. Can I get some advice.
2) I searched ASPFAQ and came up blank. Where can find the "rules"...
|
by: Gérard Leclercq |
last post by:
ACCESS
First fields are TEXT, last 2 are Numbers
The name of the fields are correct.
Dim MyConn
Set MyConn=Server.CreateObject("ADODB.Connection")
MyConn.Open...
|
by: Peter Frost |
last post by:
Please help
I don't know if this is possible but what I would really like to do is
to use On Error Goto to capture the code that is being executed when
an error occurs.
Any help would be much...
|
by: iam247 |
last post by:
Hi
I am a relative beginner with ASP and weak on syntax for sql
statements. Basically I modify something which works.
I have tblGroupContact with two fields both long integer - ContactID &...
|
by: deko |
last post by:
I'm trying to log error messages and sometimes (no telling when or where)
the message contains a string with double quotes. Is there a way get the
query to insert the string with the double...
|
by: amitbadgi |
last post by:
HI i am getting the foll error while conv an asp application to
asp.net
Exception Details: System.Runtime.InteropServices.COMException: Syntax
error in UPDATE statement.
Source Error:
Line...
|
by: amitbadgi |
last post by:
Hi guys, I am getting the following error in teh insert statement , I
am converting this asp application to asp.net, here is teh error,
Exception Details:...
|
by: ryjfgjl |
last post by:
In our work, we often receive Excel tables with data in the same format. If we want to analyze these data, it can be difficult to analyze them because the data is spread across multiple Excel files...
|
by: emmanuelkatto |
last post by:
Hi All, I am Emmanuel katto from Uganda. I want to ask what challenges you've faced while migrating a website to cloud.
Please let me know.
Thanks!
Emmanuel
|
by: nemocccc |
last post by:
hello, everyone, I want to develop a software for my android phone for daily needs, any suggestions?
|
by: marktang |
last post by:
ONU (Optical Network Unit) is one of the key components for providing high-speed Internet services. Its primary function is to act as an endpoint device located at the user's premises. However,...
|
by: Oralloy |
last post by:
Hello folks,
I am unable to find appropriate documentation on the type promotion of bit-fields when using the generalised comparison operator "<=>".
The problem is that using the GNU compilers,...
|
by: jinu1996 |
last post by:
In today's digital age, having a compelling online presence is paramount for businesses aiming to thrive in a competitive landscape. At the heart of this digital strategy lies an intricately woven...
|
by: Hystou |
last post by:
Overview:
Windows 11 and 10 have less user interface control over operating system update behaviour than previous versions of Windows. In Windows 11 and 10, there is no way to turn off the Windows...
|
by: tracyyun |
last post by:
Dear forum friends,
With the development of smart home technology, a variety of wireless communication protocols have appeared on the market, such as Zigbee, Z-Wave, Wi-Fi, Bluetooth, etc. Each...
|
by: agi2029 |
last post by:
Let's talk about the concept of autonomous AI software engineers and no-code agents. These AIs are designed to manage the entire lifecycle of a software development project—planning, coding, testing,...
| |