replace the use of StringUtil.quote(String) with StringUtil.JDBCescapeStringLiteral...
[mir.git] / source / mircoders / storage / DatabaseLinksImcs.java
index 7290782..0f7597c 100755 (executable)
@@ -114,9 +114,9 @@ public class DatabaseLinksImcs extends Database
                                                else {
                                                        if (theEntityValues.containsKey(aField)) {
                                                                if (aField.equals("to_parent_id")) {
-                                                                       aValue = StringUtil.quote((String)theEntityValues.get(aField));
+                                                                       aValue = StringUtil.JDBCescapeStringLiteral((String)theEntityValues.get(aField));
                                                                } else {
-                                                                       aValue = "'" + StringUtil.quote((String)theEntityValues.get(aField)) + "'";
+                                                                       aValue = "'" + StringUtil.JDBCescapeStringLiteral((String)theEntityValues.get(aField)) + "'";
                                                                }
                                                        }
                                                }
@@ -192,9 +192,9 @@ public class DatabaseLinksImcs extends Database
                                                firstField = false;
                                        }
                                        if (aField.equals("to_parent_id")) {
-                                               fv.append(aField).append("=").append(StringUtil.quote((String)theEntityValues.get(aField)));
+                                               fv.append(aField).append("=").append(StringUtil.JDBCescapeStringLiteral((String)theEntityValues.get(aField)));
                                        } else {
-                                               fv.append(aField).append("='").append(StringUtil.quote((String)theEntityValues.get(aField))).append("'");
+                                               fv.append(aField).append("='").append(StringUtil.JDBCescapeStringLiteral((String)theEntityValues.get(aField))).append("'");
                                        }
                                }
                        }