2021-04-19 Fred Gleason <fredg@paravelsystems.com>

* Escaped all SQL identifiers in 'rdlibrary/'.
	* Replaced " with ' delimiters in all SQL literal strings in
	'rdlibrary/'.

Signed-off-by: Fred Gleason <fredg@paravelsystems.com>
This commit is contained in:
Fred Gleason
2021-04-19 20:11:16 -04:00
parent 220ead0ccd
commit ad56584012
8 changed files with 124 additions and 125 deletions

View File

@@ -51,8 +51,8 @@ bool NoteBubble::setCartNumber(unsigned cartnum)
note_show_timer->stop();
hide();
QString sql=QString("select NOTES from CART where ")+
QString().sprintf("NUMBER=%u",cartnum);
QString sql=QString("select `NOTES` from `CART` where ")+
QString().sprintf("`NUMBER`=%u",cartnum);
RDSqlQuery *q=new RDSqlQuery(sql);
if(q->first()&&(!q->value(0).toString().trimmed().isEmpty())) {
setText(q->value(0).toString());