mirror of
https://github.com/ElvishArtisan/rivendell.git
synced 2025-11-29 08:40:12 +01:00
2021-04-19 Fred Gleason <fredg@paravelsystems.com>
* Escaped all SQL identifiers in 'rdlibrary/'. * Replaced " with ' delimiters in all SQL literal strings in 'rdlibrary/'. Signed-off-by: Fred Gleason <fredg@paravelsystems.com>
This commit is contained in:
@@ -749,9 +749,9 @@ void EditCart::okData()
|
||||
return;
|
||||
}
|
||||
if(!rda->system()->allowDuplicateCartTitles()) {
|
||||
sql=QString("select NUMBER from CART where ")+
|
||||
"(TITLE=\""+RDEscapeString(rdcart_controls.title_edit->text())+"\") &&"+
|
||||
QString().sprintf("(NUMBER!=%u)",rdcart_cart->number());
|
||||
sql=QString("select `NUMBER` from `CART` where ")+
|
||||
"(`TITLE`='"+RDEscapeString(rdcart_controls.title_edit->text())+"') &&"+
|
||||
QString().sprintf("(`NUMBER`!=%u)",rdcart_cart->number());
|
||||
q=new RDSqlQuery(sql);
|
||||
if(q->first()) {
|
||||
QMessageBox::warning(this,tr("Duplicate Title"),
|
||||
|
||||
Reference in New Issue
Block a user