quote strings passed to sql