]> err.no Git - dak/commitdiff
escape strings for comments on packages and comment authors
authorMike O'Connor <stew@vireo.org>
Thu, 14 May 2009 06:28:30 +0000 (02:28 -0400)
committerMike O'Connor <stew@vireo.org>
Thu, 14 May 2009 06:28:30 +0000 (02:28 -0400)
dak hates the name "Mike O'Connor".  This uses pg.escape_string to make it love
my name instead.

daklib/database.py

index a52555682624ca8aac8fa693acac8f805eb797f4..0be839b65cb5db0adbd0a8b2baf31878af0f1032 100755 (executable)
@@ -907,7 +907,7 @@ def add_new_comment(package, version, comment, author):
 
     projectB.query(""" INSERT INTO new_comments (package, version, comment, author)
                        VALUES ('%s', '%s', '%s', '%s')
-    """ % (package, version, comment, author) )
+    """ % (package, version, pg.escape_string(comment), pg.escape_string(author)))
 
     return