b651efa6dd03dea5a8470ba80b4720bddbb999a3 galt Thu Aug 15 17:18:52 2013 -0700 fixing minor anti-sqli problems diff --git src/hg/qaPushQ/qaPushQ.c src/hg/qaPushQ/qaPushQ.c index 44edbb2..9057f87 100644 --- src/hg/qaPushQ/qaPushQ.c +++ src/hg/qaPushQ/qaPushQ.c @@ -3284,31 +3284,31 @@ void doDrawReleaseLog(boolean isEncode) /* Test - draw the release log using log data in pushQ */ { char *centraldb = NULL; char *chost = NULL; char *cuser = NULL; char *cpassword = NULL; struct sqlConnection *betaconn = NULL; struct dbDb *ki=NULL, *kiList=NULL, *dbDbTemp=NULL; struct sqlResult *sr; char **row; -char query[256]; +char query[1024]; char tempName[256]; char now[256]; int m=0,d=0; int topCount=0; char *encodeClause = ""; if (isEncode) encodeClause = " and releaseLog like '%ENCODE%'"; ZeroVar(&dbDbTemp); chost = cfgOption("rrcentral.host" ); @@ -3346,31 +3346,31 @@ // are we really only allowed one remoteconn at a time? conn = sqlConnectRemote(host, user, password, database); /* filter the db list to make sure we actually have data */ struct dbDb *newList=NULL, *kiNext; for (ki = kiList; ki != NULL; ki = kiNext) { kiNext = ki->next; sqlSafef(query,sizeof(query), "select count(*) from pushQ " "where priority='L' and releaseLog != '' and (" "dbs like '%s' or " "dbs like '%s %%' or " "dbs like '%% %s' or " "dbs like '%% %s %%'" - ") %s" + ") %-s" "order by qadate desc, qid desc", ki->name, ki->name, ki->name, ki->name, encodeClause ); if (sqlQuickNum(conn, query) > 0) { slAddHead(&newList, ki); } } slReverse(&newList); kiList = newList; /* 10 Latest Changes */ @@ -3396,31 +3396,31 @@ strftime (now, sizeof(now), "%02d %b %Y", loctime); /* default to today's date */ printf("Last updated %s. Inquiries and feedback welcome.\n",now); /* 10 LATEST CHANGES */ webNewSection(" 10 Latest Changes (all assemblies)"); printf("