Table of Contents

Class SoqlHelpers

Namespace
NetCoreForce.Client
Assembly
NetCoreForce.Client.dll

Helpers for safely including values in SOQL and SOSL queries.

Always escape values that come from user input or other untrusted sources before adding them to a query string, to prevent SOQL/SOSL injection.

public static class SoqlHelpers
Inheritance
SoqlHelpers
Inherited Members

Methods

EscapeLike(string)

Escape a value for use inside a quoted SOQL LIKE pattern, so that any _ and % characters in the value are matched literally.

Example: $"SELECT Id FROM Account WHERE Name LIKE '{SoqlHelpers.EscapeLike(prefix)}%'"

public static string EscapeLike(string value)

Parameters

value string

Value to escape

Returns

string

Escaped value, without surrounding quotes or wildcards

EscapeSosl(string)

Escape a search term for use inside a SOSL FIND clause, so that reserved characters are matched literally.

Example: $"FIND {{{SoqlHelpers.EscapeSosl(term)}}} IN NAME FIELDS RETURNING Account (Id, Name)"

public static string EscapeSosl(string value)

Parameters

value string

Search term to escape

Returns

string

Escaped search term, without surrounding braces

EscapeString(string)

Escape a value for use inside a quoted SOQL string literal.

Example: $"SELECT Id FROM Account WHERE Name = '{SoqlHelpers.EscapeString(name)}'"

public static string EscapeString(string value)

Parameters

value string

Value to escape

Returns

string

Escaped value, without surrounding quotes