{"Entry":{"collection":"guc","key":"backslash_quote","name":"backslash_quote","aliases":[],"metadata":{"baseline":true,"boot_human":"Not specified","boot_val":null,"category":"Version and Platform Compatibility / Previous PostgreSQL Versions","category_zh":"","changed_in":[],"changes":[{"documentation_changed":true,"fields":{},"from":"8.1","status":"changed","to":"8.2"},{"documentation_changed":true,"fields":{},"from":"8.4","status":"changed","to":"9.0"},{"documentation_changed":true,"fields":{},"from":"13","status":"changed","to":"14"},{"documentation_changed":true,"fields":{},"from":"18","status":"changed","to":"19"}],"content_hash":"de35baad13d510c258ce792631ee55494600dca0b47a43bc76e26e6f4aa16160","context":"","default_changed_in":[],"default_history":[{"from":"9.0","to":"19","value":"safe_encoding"}],"editorial":{"advice":{"olap":"Regression-test ETL, generated SQL, and old drivers, where parsing/quoting assumptions hide. Performance is rarely a reason to change this switch.","oltp":"Keep the modern default and repair legacy clients/SQL that depend on backslash_quote. Test migration at session scope first; do not make a compatibility switch permanent cluster policy.","small":"Keep the default without a legacy requirement. If temporarily enabled, record owner, affected connections, and a removal date."},"mechanism":["Sets whether \"\\'\" is allowed in string literals. It can be changed at session scope, so different sessions may observe different behavior.","The safe_encoding mode accepts \\' only when the client encoding cannot contain a backslash byte inside a multibyte character. This defense belongs to old string-literal syntax; E'...' is the explicit escape-string form and standard_conforming_strings governs ordinary strings.","Monitor and change backslash_quote together with array_nulls, escape_string_warning, standard_conforming_strings. Validate on the relevant server role and real workload, then use its user context to choose session change, reload, or restart; a historical boot default is not the current effective value."],"pitfalls":["Keeping a compatibility switch permanently instead of fixing the client.","Testing in one session and deploying globally to unrelated applications.","Confusing parsing compatibility with data or security compatibility.","Forgetting to remove an override after the upgrade migration is complete."],"references":[{"title":"PostgreSQL 19 Beta 4: backslash_quote","url":"https://www.postgresql.org/docs/19/runtime-config-compatible.html#GUC-BACKSLASH-QUOTE"},{"title":"PostgreSQL 19 release notes","url":"https://www.postgresql.org/docs/19/release-19.html"}],"related":["array_nulls","escape_string_warning","standard_conforming_strings","transform_null_equals","quote_all_identifiers","default_with_oids"],"summary":"backslash_quote — Sets whether \"\\'\" is allowed in string literals. Observed in PG9.0–19 Beta 4; its last measured boot default is safe_encoding in PG19 Beta 4, with user context. This is a beta-snapshot fact and can change before PostgreSQL 19 GA."},"enumvals":[],"first_version":"7.4","group":"Version and Platform Compatibility","group_slug":"compatible","imported_at":"2026-09-27T17:57:30.860727+08:00","intro_commit":{},"key":"backslash_quote","last_version":"20","max_val":"","min_val":"","name":"backslash_quote","position":39,"present_in":["7.4","8.0","8.1","8.2","8.3","8.4","9.0","9.1","9.2","9.3","9.4","9.5","9.6","10","11","12","13","14","15","16","17","18","19","20"],"short_desc":"This controls whether a quote mark can be represented by \\' in a string literal.","short_desc_zh":"","source_rev":"english-manuals:4bd2144128de25d36742fcdfa375bf0f8b9ffff0865b58df98c7390bb8062647","unit":"","vartype":"enum"}},"Definition":{"Collection":"guc","Key":"backslash_quote","SourceDatabase":"center","Version":"18","SourceTable":"guc","SourceKey":"backslash_quote","SourceRevision":"english-manuals:4bd2144128de25d36742fcdfa375bf0f8b9ffff0865b58df98c7390bb8062647","Facts":{"boot_val":"safe_encoding","category":"Version and Platform Compatibility / Previous PostgreSQL Versions","context":"user","description":"This controls whether a quote mark can be represented by \\' in a string literal. The preferred, SQL-standard way to represent a quote mark is by doubling it ('') but PostgreSQL has historically also accepted \\'. However, use of \\' creates security risks because in some client character set encodings, there are multibyte characters in which the last byte is numerically equivalent to ASCII \\. If client-side code does escaping incorrectly then an SQL-injection attack is possible. This risk can be prevented by making the server reject queries in which a quote mark appears to be escaped by a backslash. The allowed values of backslash_quote are on (allow \\' always), off (reject always), and safe_encoding (allow only if client encoding does not allow ASCII \\ within a multibyte character). safe_encoding is the default setting. Note that in a standard-conforming string literal, \\ just means \\ anyway. This parameter only affects the handling of non-standard-conforming literals, including escape string syntax (E'...').","doc":{"anchor":"GUC-BACKSLASH-QUOTE","file":"runtime-config-compatible.html","lang":"en","sha256":"db2ecac1e62738d66a4932f4c8197976a349bcbf261c5b90fff740bc44867b8b","slug":"18"},"documented":true,"enumvals":["safe_encoding","on","off"],"extra_desc":null,"lang":"en","max_val":null,"metadata_version":"18","min_val":null,"name":"backslash_quote","short_desc":"Sets whether \"\\'\" is allowed in string literals.","source":"pg-settings-source-snapshot","unit":null,"vartype":"enum"},"ManualEvidence":{"doc":{"anchor":"GUC-BACKSLASH-QUOTE","file":"runtime-config-compatible.html","lang":"en","sha256":"db2ecac1e62738d66a4932f4c8197976a349bcbf261c5b90fff740bc44867b8b","slug":"18"}},"MeasuredEvidence":{"metadata_version":"18"}},"Text":{"Collection":"guc","Key":"backslash_quote","SourceDatabase":"center","Version":"18","Locale":"en","Title":"backslash_quote","Summary":"This controls whether a quote mark can be represented by \\' in a string literal. The preferred, SQL-standard way to represent a quote mark is by doubling it ('') but PostgreSQL has historically also accepted \\'. However, use of \\' creates security risks because in some client character set encodings, there are multibyte characters in which the last byte is numerically equivalent to ASCII \\. If client-side code does escaping incorrectly then an SQL-injection attack is possible. This risk can be prevented by making the server reject queries in which a quote mark appears to be escaped by a backslash. The allowed values of backslash_quote are on (allow \\' always), off (reject always), and safe_encoding (allow only if client encoding does not allow ASCII \\ within a multibyte character). safe_encoding is the default setting. Note that in a standard-conforming string literal, \\ just means \\ anyway. This parameter only affects the handling of non-standard-conforming literals, including escape string syntax (E'...').","BodyHTML":"\u003cp\u003eThis controls whether a quote mark can be represented by \\\u0026#39; in a string literal. The preferred, SQL-standard way to represent a quote mark is by doubling it (\u0026#39;\u0026#39;) but PostgreSQL has historically also accepted \\\u0026#39;. However, use of \\\u0026#39; creates security risks because in some client character set encodings, there are multibyte characters in which the last byte is numerically equivalent to ASCII \\. If client-side code does escaping incorrectly then an SQL-injection attack is possible. This risk can be prevented by making the server reject queries in which a quote mark appears to be escaped by a backslash. The allowed values of backslash_quote are on (allow \\\u0026#39; always), off (reject always), and safe_encoding (allow only if client encoding does not allow ASCII \\ within a multibyte character). safe_encoding is the default setting. Note that in a standard-conforming string literal, \\ just means \\ anyway. This parameter only affects the handling of non-standard-conforming literals, including escape string syntax (E\u0026#39;...\u0026#39;).\u003c/p\u003e","SourceRevision":"english-manuals:4bd2144128de25d36742fcdfa375bf0f8b9ffff0865b58df98c7390bb8062647","ContentHash":"3c6b34085ae97594fd0cdc232a1dc9f6b767d30cd6399724fe4f1c083c5707eb","Payload":{"description":"This controls whether a quote mark can be represented by \\' in a string literal. The preferred, SQL-standard way to represent a quote mark is by doubling it ('') but PostgreSQL has historically also accepted \\'. However, use of \\' creates security risks because in some client character set encodings, there are multibyte characters in which the last byte is numerically equivalent to ASCII \\. If client-side code does escaping incorrectly then an SQL-injection attack is possible. This risk can be prevented by making the server reject queries in which a quote mark appears to be escaped by a backslash. The allowed values of backslash_quote are on (allow \\' always), off (reject always), and safe_encoding (allow only if client encoding does not allow ASCII \\ within a multibyte character). safe_encoding is the default setting. Note that in a standard-conforming string literal, \\ just means \\ anyway. This parameter only affects the handling of non-standard-conforming literals, including escape string syntax (E'...')."}},"RequestedLocale":"zh-Hans","Fallback":true,"Versions":["10","11","12","13","14","15","16","17","18","19","20","7.4","8.0","8.1","8.2","8.3","8.4","9.0","9.1","9.2","9.3","9.4","9.5","9.6"],"Locales":["en"],"Signatures":null,"Spellings":null,"SQLState":null,"Evidence":null}
