2021-04-18 Fred Gleason <fredg@paravelsystems.com>

* Escaped all SQL identifiers in 'rdadmin/'.
	* Replaced " with ' delimiters in all SQL literal strings in
	'rdadmin/'.

Signed-off-by: Fred Gleason <fredg@paravelsystems.com>
This commit is contained in:
Fred Gleason
2021-04-18 21:23:19 -04:00
parent 0fd02861f9
commit 6264ec3235
67 changed files with 841 additions and 939 deletions

View File

@@ -131,7 +131,7 @@ void ListDropboxes::addData()
delete notify;
}
else {
QString sql=QString().sprintf("delete from DROPBOXES where ID=%d",id);
QString sql=QString().sprintf("delete from `DROPBOXES` where `ID`=%d",id);
RDSqlQuery *q=new RDSqlQuery(sql);
delete q;
delete edit_dropbox;
@@ -186,7 +186,7 @@ void ListDropboxes::duplicateData()
delete notify;
}
else {
QString sql=QString().sprintf("delete from DROPBOXES where ID=%d",
QString sql=QString().sprintf("delete from `DROPBOXES` where `ID`=%d",
new_box_id);
RDSqlQuery::apply(sql);
}
@@ -203,11 +203,11 @@ void ListDropboxes::deleteData()
return;
}
int box_id=list_dropboxes_model->dropboxId(rows.first());
sql=QString().sprintf("delete from DROPBOX_PATHS where DROPBOX_ID=%d",
sql=QString().sprintf("delete from `DROPBOX_PATHS` where `DROPBOX_ID`=%d",
box_id);
RDSqlQuery::apply(sql);
sql=QString().sprintf("delete from DROPBOXES where ID=%d",box_id);
sql=QString().sprintf("delete from `DROPBOXES` where `ID`=%d",box_id);
RDSqlQuery::apply(sql);
list_dropboxes_model->removeDropbox(box_id);