forked from bton/matekasse
Fic sql injektions
This commit is contained in:
parent
31e14e7757
commit
36da985835
1 changed files with 2 additions and 2 deletions
4
main.py
4
main.py
|
@ -59,7 +59,7 @@ def list():
|
|||
@app.route("/list/user", methods=['GET'])
|
||||
def user_info():
|
||||
username = request.args.get("user")
|
||||
c.execute("SELECT * FROM users WHERE username = '%s'" % username)
|
||||
c.execute("SELECT * FROM users WHERE username = '%(username)s'", {'username':username})
|
||||
user_list = c.fetchall()
|
||||
if user_list != []:
|
||||
user = user_list[0]
|
||||
|
@ -114,7 +114,7 @@ def adduser():
|
|||
user = request.args.get("username")
|
||||
c.execute(f"SELECT * FROM users WHERE username='{str(user)}'")
|
||||
if c.fetchall() == []:
|
||||
c.execute("INSERT or IGNORE INTO users (username, balance) VALUES ('%s', 0)" % user)
|
||||
c.execute("INSERT or IGNORE INTO users (username, balance) VALUES ('%(user)s', 0)", {'user' : user} )
|
||||
conn.commit()
|
||||
return 'Added user <a href="/list">user and tag list</a> <p>The creator of this website accepts no liability for any linguistic or technical errors!</p>'
|
||||
else:
|
||||
|
|
Loading…
Reference in a new issue