]> git.ipfire.org Git - pbs.git/commitdiff
Remove any backticks for MySQL escaping
authorMichael Tremer <michael.tremer@ipfire.org>
Sat, 7 Oct 2017 13:26:56 +0000 (14:26 +0100)
committerMichael Tremer <michael.tremer@ipfire.org>
Sat, 7 Oct 2017 13:26:56 +0000 (14:26 +0100)
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
src/buildservice/arches.py
src/buildservice/keys.py
src/buildservice/messages.py
src/buildservice/packages.py
src/buildservice/users.py

index 2ec4b2029db225086496f303299e84a861da0a65..b06fd73844bcb236702c3201674319da9104c35b 100644 (file)
@@ -7,7 +7,7 @@ class Arches(base.Object):
                query = "SELECT * FROM arches"
 
                if not really:
-                       query += " WHERE `binary` = 'Y'"
+                       query += " WHERE binary = 'Y'"
                else:
                        query += " WHERE NOT name = 'src'"
 
index 21d0e9b7580d4c6dc48ca3ebbf7980668273c899..7f4ba7884dea063b1205614c1fa044125b02e133 100644 (file)
@@ -38,7 +38,7 @@ class Keys(base.Object):
                return Key.create(self.pakfire, *args, **kwargs)
 
        def get_all(self):
-               query = self.db.query("SELECT id FROM `keys` ORDER BY uids")
+               query = self.db.query("SELECT id FROM keys ORDER BY uids")
 
                keys = []
                for key in query:
@@ -48,7 +48,7 @@ class Keys(base.Object):
                return keys
 
        def get_by_id(self, id):
-               key = self.db.get("SELECT id FROM `keys` WHERE id = %s", id)
+               key = self.db.get("SELECT id FROM keys WHERE id = %s", id)
                if not key:
                        return
 
@@ -57,7 +57,7 @@ class Keys(base.Object):
        def get_by_fpr(self, fpr):
                fpr = "%%%s" % fpr
 
-               key = self.db.get("SELECT id FROM `keys` WHERE fingerprint LIKE %s", fpr)
+               key = self.db.get("SELECT id FROM keys WHERE fingerprint LIKE %s", fpr)
                if not key:
                        return
 
@@ -89,7 +89,7 @@ class Key(base.Object):
                        return k
 
                # Insert new into the database.
-               key_id = pakfire.db.execute("INSERT INTO `keys`(fingerprint, uids, data) \
+               key_id = pakfire.db.execute("INSERT INTO keys(fingerprint, uids, data) \
                        VALUES(%s, %s, %s)", fingerprint, ", ".join([u.uid for u in key.uids]), data)
 
                key = cls(pakfire, key_id)
@@ -100,7 +100,7 @@ class Key(base.Object):
        @property
        def data(self):
                if self._data is None:
-                       self._data = self.db.get("SELECT * FROM `keys` WHERE id = %s", self.id)
+                       self._data = self.db.get("SELECT * FROM keys WHERE id = %s", self.id)
                        assert self._data
 
                return self._data
@@ -126,7 +126,7 @@ class Key(base.Object):
                                time_created, time_expires, algo) VALUES(%s, %s, %s, %s, %s)",
                                self.id, subkey.keyid, time_created, time_expires, algo)
 
-               self.db.execute("UPDATE `keys` SET fingerprint = %s, uids = %s, data = %s WHERE id = %s",
+               self.db.execute("UPDATE keys SET fingerprint = %s, uids = %s, data = %s WHERE id = %s",
                        fingerprint, ", ".join([u.uid for u in key.uids]), data, self.id)
 
        def can_be_deleted(self):
@@ -140,8 +140,8 @@ class Key(base.Object):
        def delete(self):
                assert self.can_be_deleted()
 
-               self.db.execute("DELETE FROM `keys_subkeys` WHERE key_id = %s", self.id)
-               self.db.execute("DELETE FROM `keys` WHERE id = %s", self.id)
+               self.db.execute("DELETE FROM keys_subkeys WHERE key_id = %s", self.id)
+               self.db.execute("DELETE FROM keys WHERE id = %s", self.id)
 
        @property
        def fingerprint(self):
index 20e59b1844ea200a4db0738e61018e55810c7fd5..4842574aad94901e97512bf6233c60f909535a1d 100644 (file)
@@ -17,7 +17,7 @@ class Messages(base.Object):
                if not frm:
                        frm = self.pakfire.settings.get("email_from")
 
-               self.db.execute("INSERT INTO user_messages(frm, `to`, subject, text)"
+               self.db.execute("INSERT INTO user_messages(frm, to, subject, text)"
                        " VALUES(%s, %s, %s, %s)", frm, to, subject, text)
 
        def get_all(self, limit=None):
@@ -116,4 +116,4 @@ class Messages(base.Object):
                        raise Exception, "Could not send mail: %s" % stderr
 
                # If everything was okay, we can delete the message in the database.
-               self.delete(msg.id)
\ No newline at end of file
+               self.delete(msg.id)
index 7bdd6d7e7692d465df36407b70961a4124ef13dc..e9b2232bc837af515ad489da7d686ca30e7b78fe 100644 (file)
@@ -184,7 +184,7 @@ class Package(base.Object):
                keys = []
                vals = []
                for key, val in query:
-                       keys.append("`%s`" % key)
+                       keys.append(key)
                        vals.append(val)
 
                _query = "INSERT INTO packages(%s)" % ", ".join(keys)
@@ -233,7 +233,7 @@ class Package(base.Object):
                                f.capabilities))
 
                _pakfire.db.executemany("INSERT INTO filelists(pkg_id, name, size, hash_sha512, \
-                       type, config, mode, user, `group`, mtime, capabilities) \
+                       type, config, mode, user, group, mtime, capabilities) \
                        VALUES(%s, %s, %s, %s, %s, %s, %s, %s, %s, %s, %s)", filelist)
 
                # Return the newly created object.
index 98ccf51337924edeed62fbe9887b9e0a3f2b5501..8af92d70237d5b23d5be790365f3a7737033a1b4 100644 (file)
@@ -246,7 +246,7 @@ class User(base.Object):
                        VALUES(%s, %s, %s)", name, generate_password_hash(passphrase), realname)
 
                # Add email address.
-               pakfire.db.execute("INSERT INTO users_emails(user_id, email, `primary`) \
+               pakfire.db.execute("INSERT INTO users_emails(user_id, email, primary) \
                        VALUES(%s, %s, 'Y')", id, email)
 
                # Create row in permissions table.