string _quote(string s)
Escape a string to prevent SQL injection, using the current connection's character encoding settings.