Opened 8 years ago

Closed 5 years ago

SQL Improvements

Reported by: Owned by: Martin Scharrer obs normal RenameTracUsersScript normal sql, patch 0.11

Description

Hi,

I would change the SQL code as follows to e.g. make sure that user input cannot be taken as SQL commands. The trick is to insert the values which need to be constant for SQL first with pythons string substitution, but then provide the user input as arguments to cursor.execute().

I didn't had the time and chance to fully test the patch yet, but I should get the point.

comment:1 Changed 5 years ago by Ryan J Ollos

Resolution: → wontfix new → closed

Plugin is deprecated, see #10901.

Modify Ticket

Change Properties