2021-04-19 Fred Gleason <fredg@paravelsystems.com>

* Escaped all SQL identifiers in 'rdairplay/'.
	* Replaced " with ' delimiters in all SQL literal strings in
	'rdairplay/'.

Signed-off-by: Fred Gleason <fredg@paravelsystems.com>
This commit is contained in:
Fred Gleason
2021-04-19 18:44:14 -04:00
parent a1ce33e344
commit 3e0c293c09
3 changed files with 10 additions and 6 deletions

View File

@@ -115,8 +115,8 @@ int ListLogs::exec(QString *logname,QString *svcname,RDLogLock **log_lock)
list_log_lock=log_lock;
list_saveas_button->setEnabled(rda->user()->createLog());
QStringList services_list;
QString sql=QString("select SERVICE_NAME from SERVICE_PERMS where ")+
"STATION_NAME=\""+RDEscapeString(rda->station()->name())+"\"";
QString sql=QString("select `SERVICE_NAME` from `SERVICE_PERMS` where ")+
"`STATION_NAME`='"+RDEscapeString(rda->station()->name())+"'";
RDSqlQuery *q=new RDSqlQuery(sql);
services_list.push_back(tr("ALL"));
while(q->next()) {