# Array

**URL:** <https://rubytalk.org/t/array/51859>\
**Category:** ruby-talk\
**Created:** [20 February 2009 16:33 UTC](https://rubytalk.org/t/array/51859 "2009-02-20T16:33:34Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Vetrivel\_Vaithilinga](https://avatars.discourse-cdn.com/v4/letter/v/958977/32.png) [@Vetrivel\_Vaithilinga](https://rubytalk.org/u/Vetrivel_Vaithilinga)\
**Post date:** [20 February 2009 16:33 UTC](https://rubytalk.org/t/array/51859/1 "2009-02-20T16:33:34Z")

</div>

In array I have content like this

&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;a = ["c" , "d", "e" , "f"]  
But I need like this

&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;'c','d','e','f'

I want this for my following purpose  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;insert into tablename values a .

a has to subtitude in below statement,.

> **···**
>
> --  
> Posted via [http://www.ruby-forum.com/](http://www.ruby-forum.com/).

---

<div class="post-metadata">

**Author:** ![lasitha](https://avatars.discourse-cdn.com/v4/letter/l/4af34b/32.png) [@lasitha](https://rubytalk.org/u/lasitha)\
**Post date:** [20 February 2009 18:19 UTC](https://rubytalk.org/t/array/51859/2 "2009-02-20T18:19:13Z")

</div>

While the ruby to do that is trivial, i feel its more important that i  
point out you should \_never\_ construct a SQL statement like this -  
it's a classic security hole.

[SQL injection - Wikipedia](http://en.wikipedia.org/wiki/SQL_injection) or just google sql injection.

Whatever tool you're using to interface with your database, it will  
certainly have a safe way to pass parameters into a sql statement.  
Please look that up - it will make the world safer and bypass your  
original problem to boot 🙂

Cheers,  
lasitha

> **···**
>
> On Fri, Feb 20, 2009 at 10:03 PM, Vetrivel Vetrivel \<vetrivel.bksys@gmail.com\> wrote:
> 
> > In array I have content like this
> > 
> > &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;a = ["c" , "d", "e" , "f"]  
> > But I need like this
> > 
> > &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;'c','d','e','f'
> > 
> > I want this for my following purpose  
> > &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;insert into tablename values a .
