Escaping a single quote when using JdbcTemplate

Viewed 9014

We're using JdbcTemplate to modify our underlying Oracle database. We're doing this by way of the update(String sql) method.

The code looks somehow like the following:

String name = "My name's yellow";
String sql = "update FIELD set NAME = '" + name "' where ID = 10
jdbcTemplate.update(sql);

This causes the error:

java.sql.SQLException: ORA-00933: SQL command not properly ended

The problem is the unescaped ' in the name variable.

What's the most convenient and correct way to escape this character?

2 Answers
Related