2021-04-18 Fred Gleason <fredg@paravelsystems.com>

* Escaped all SQL identifiers in 'rdadmin/'.
	* Replaced " with ' delimiters in all SQL literal strings in
	'rdadmin/'.

Signed-off-by: Fred Gleason <fredg@paravelsystems.com>
This commit is contained in:
Fred Gleason
2021-04-18 21:23:19 -04:00
parent 0fd02861f9
commit 6264ec3235
67 changed files with 841 additions and 939 deletions

View File

@@ -129,11 +129,11 @@ void ListSchedCodes::addData()
}
}
else {
QString sql=QString("delete from SCHED_CODES where ")+
"CODE=\""+RDEscapeString(scode)+"\"";
QString sql=QString("delete from `SCHED_CODES` where ")+
"`CODE`='"+RDEscapeString(scode)+"'";
RDSqlQuery::apply(sql);
sql=QString("delete from RULE_LINES where ")+
"CODE=\""+RDEscapeString(scode)+"\"";
sql=QString("delete from `RULE_LINES` where ")+
"`CODE`='"+RDEscapeString(scode)+"'";
RDSqlQuery::apply(sql);
}
}
@@ -175,16 +175,16 @@ void ListSchedCodes::deleteData()
return;
}
sql=QString("delete from DROPBOX_SCHED_CODES where ")+
"SCHED_CODE=\""+RDEscapeString(codename)+"\"";
sql=QString("delete from `DROPBOX_SCHED_CODES` where ")+
"`SCHED_CODE`='"+RDEscapeString(codename)+"'";
RDSqlQuery::apply(sql);
sql=QString("delete from RULE_LINES where ")+
"CODE=\""+RDEscapeString(codename)+"\"";
sql=QString("delete from `RULE_LINES` where ")+
"`CODE`='"+RDEscapeString(codename)+"'";
RDSqlQuery::apply(sql);
sql=QString("delete from SCHED_CODES where ")+
"CODE=\""+RDEscapeString(codename)+"\"";
sql=QString("delete from `SCHED_CODES` where ")+
"`CODE`='"+RDEscapeString(codename)+"'";
RDSqlQuery::apply(sql);
list_schedcodes_model->removeSchedCode(rows.first());
}