forked from bton/matekasse
SQL injektionn
This commit is contained in:
parent
36da985835
commit
d108bca11d
1 changed files with 1 additions and 1 deletions
2
main.py
2
main.py
|
@ -112,7 +112,7 @@ def remove_user():
|
||||||
@app.route("/adduser/user", methods=['GET'])
|
@app.route("/adduser/user", methods=['GET'])
|
||||||
def adduser():
|
def adduser():
|
||||||
user = request.args.get("username")
|
user = request.args.get("username")
|
||||||
c.execute(f"SELECT * FROM users WHERE username='{str(user)}'")
|
c.execute(f"SELECT * FROM users WHERE username='%users'", {'user' : user})
|
||||||
if c.fetchall() == []:
|
if c.fetchall() == []:
|
||||||
c.execute("INSERT or IGNORE INTO users (username, balance) VALUES ('%(user)s', 0)", {'user' : user} )
|
c.execute("INSERT or IGNORE INTO users (username, balance) VALUES ('%(user)s', 0)", {'user' : user} )
|
||||||
conn.commit()
|
conn.commit()
|
||||||
|
|
Loading…
Reference in a new issue