SQL Improvements

Description

Hi,

I would change the SQL code as follows to e.g. make sure that user input cannot be taken as SQL commands. The trick is to insert the values which need to be constant for SQL first with pythons string substitution, but then provide the user input as arguments to cursor.execute().

I didn't had the time and chance to fully test the patch yet, but I should get the point.

Changed 5 years ago by Ryan J Ollos

Resolution: → wontfix new → closed

Plugin is deprecated, see #10901.

