ef7ce6e04d479590353139876d0fa409b861b259 galt Wed Jun 12 14:10:52 2013 -0700 removing unneeded fix-sqli functions diff --git src/hg/lib/mdb.c src/hg/lib/mdb.c index bcae6d9..544e43c 100644 --- src/hg/lib/mdb.c +++ src/hg/lib/mdb.c @@ -1030,31 +1030,31 @@ else if (!sqlTableExists(conn,tableName)) errAbort("mdbObjsSetToDb attempting to update non-existent table named '%s'.\n",tableName); // Table specific lock (over-cautious, since most work is done on sandbox tables) char lock[64]; safef(lock,sizeof lock,"lock_%s",tableName); sqlGetLock(conn, lock); for (mdbObj = mdbObjs;mdbObj != NULL; mdbObj = mdbObj->next) { // Handle delete requests first if (mdbObj->deleteThis) { if (mdbObj->vars == NULL) // deletes all { - sqlSafef(query, sizeof(query),"%s where obj = '%s'",sqlCheckTableName(tableName),sqlCheckQuotedLiteral(mdbObj->obj)); // NOSQLINJ + sqlSafefFrag(query, sizeof(query),"%s where obj = '%s'", tableName, mdbObj->obj); int delCnt = sqlRowCount(conn,query); if (delCnt>0) { sqlSafef(query, sizeof(query), "delete from %s where obj = '%s'",tableName,mdbObj->obj); verbose(2, "Requesting delete of %d rows:\n\t%s;\n",delCnt, query); if (!testOnly) sqlUpdate(conn, query); count += delCnt; } } else // deletes selected vars { for (mdbVar = mdbObj->vars;mdbVar != NULL; mdbVar = mdbVar->next) @@ -1066,31 +1066,31 @@ { sqlSafef(query, sizeof(query), "delete from %s where obj = '%s' and var = '%s'", tableName,mdbObj->obj,mdbVar->var); verbose(2, "Requesting delete of 1 row:\n\t%s;\n",query); if (!testOnly) sqlUpdate(conn, query); count++; } } } continue; // Done with this mdbObj } else if (replace) // If replace then clear out deadwood before inserting new vars { - sqlSafef(query, sizeof(query),"%s where obj = '%s'",sqlCheckTableName(tableName),sqlCheckQuotedLiteral(mdbObj->obj)); // NOSQLINJ + sqlSafefFrag(query, sizeof(query),"%s where obj = '%s'", tableName, mdbObj->obj); int delCnt = sqlRowCount(conn,query); if (delCnt>0) { sqlSafef(query, sizeof(query), "delete from %s where obj = '%s'",tableName,mdbObj->obj); verbose(2, "Requesting replacement of %d rows:\n\t%s;\n",delCnt, query); if (!testOnly) sqlUpdate(conn, query); count += delCnt; } } // Now it is time for update or add! for (mdbVar = mdbObj->vars;mdbVar != NULL; mdbVar = mdbVar->next)