diff options
author | zsloan | 2015-06-29 10:37:20 -0500 |
---|---|---|
committer | zsloan | 2015-06-29 10:37:20 -0500 |
commit | b8152f98f0d9c2a1ec0d73145a4670153b60a307 (patch) | |
tree | f2e419a375b87a361c9288a9defd7bb46fade4b2 /wqflask/base/trait.py | |
parent | 1353414114b9595a1b207ae4da28e5e725edc550 (diff) | |
parent | a41f9323ea5b86be6d2139a927586630b222af68 (diff) | |
download | genenetwork2-b8152f98f0d9c2a1ec0d73145a4670153b60a307.tar.gz |
Merge pull request #77 from lomereiter/fix_sql
SQL security fixes
Diffstat (limited to 'wqflask/base/trait.py')
-rwxr-xr-x | wqflask/base/trait.py | 9 |
1 files changed, 5 insertions, 4 deletions
diff --git a/wqflask/base/trait.py b/wqflask/base/trait.py index 7f1170a9..7689a469 100755 --- a/wqflask/base/trait.py +++ b/wqflask/base/trait.py @@ -299,6 +299,7 @@ class GeneralTrait(object): """ % (self.name, self.dataset.id) print("query is:", query) + assert self.name.isdigit() trait_info = g.db.execute(query).fetchone() #XZ, 05/08/2009: Xiaodong add this block to use ProbeSet.Id to find the probeset instead of just using ProbeSet.Name @@ -337,10 +338,10 @@ class GeneralTrait(object): trait_info = g.db.execute(query).fetchone() #print("trait_info is: ", pf(trait_info)) else: #Temp type - query = """SELECT %s FROM %s WHERE Name = %s - """ % (string.join(self.dataset.display_fields,','), - self.dataset.type, self.name) - trait_info = g.db.execute(query).fetchone() + query = """SELECT %s FROM %s WHERE Name = %s""" + trait_info = g.db.execute(query, + (string.join(self.dataset.display_fields,','), + self.dataset.type, self.name)).fetchone() if trait_info: self.haveinfo = True |