Skip to content

Commit 490db2c

Browse files
Plug SQLi in test utility function (#31)
1 parent 4f9958e commit 490db2c

1 file changed

Lines changed: 4 additions & 3 deletions

File tree

test/test_docset.py

Lines changed: 4 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -59,12 +59,13 @@ def _test_a_doc_page_index(
5959
contains_lenient: list[tuple[str,str]] | None = None,
6060
not_contains: list[tuple[str,str]] | None = None,
6161
):
62-
sql = f'''
62+
sql = '''
6363
SELECT type, name
6464
FROM searchIndex
65-
WHERE path LIKE '{path}#%'
65+
WHERE path LIKE :path_like
6666
'''
67-
res = self.cur.execute(sql)
67+
data = {'path_like': f'{path}#%'}
68+
res = self.cur.execute(sql, data)
6869
items = res.fetchall()
6970

7071
for pair in contains_lenient or []:

0 commit comments

Comments
 (0)