Re: [PATCH] dlr_mysql.c - Table name fix

Vincent CHAVANIS <[email protected]>
Newsgroups gmane.comp.mobile.kannel.devel
Message-ID <[email protected]>
Ok, attached the new patch here.

Vincent.


Alexander Malysh a écrit :
> 
> Am 13.10.2009 um 00:09 schrieb Vincent CHAVANIS:
> 
>>
>> I'm sure we will find other specific cases that will be processed into 
>> this function ;)
>> Let it as it.
> 
> Vincent, sorry but I don't see reason and case that we will add there. 
> Please consider to kill function call
> or show me another functional line in this function...
> 
> We always can easy add this function again if we find any case that we 
> have to escape...
> 
>>
>> Vincent.
>>
>>
>> Alexander Malysh a écrit :
>>> hmm, you make it tooo complicated ;)
>>> why not just:
>>> octstr_replace(fields->table, octstr_imm("`"), octstr_imm("``"));
>>> ...
>>> instead of calling function/macro with only one line?
>>> Thanks,
>>> Alex
>>> Am 12.10.2009 um 13:45 schrieb Vincent CHAVANIS:
>>>>
>>>> done.
>>>>
>>>> Vincent
>>>>
>>>>
>>>> Alexander Malysh a écrit :
>>>>> Hi again,
>>>>> I don't see reason to use macro because macro contains only one 
>>>>> line...
>>>>> Could you please drop macro and use plain function call?
>>>>> Thanks,
>>>>> Alex
>>>>> Am 12.10.2009 um 12:39 schrieb Vincent CHAVANIS:
>>>>>>
>>>>>> Damn! you're right ;-)
>>>>>>
>>>>>> For this issue, i decided to use a macro that
>>>>>> replaces names during the init process
>>>>>>
>>>>>> Comments ?
>>>>>>
>>>>>> Vincent.
>>>>>>
>>>>>>
>>>>>> Alexander Malysh a écrit :
>>>>>>> Hi,
>>>>>>> +1 for this patch but patch is not complete. It doesn't handle 
>>>>>>> this case:
>>>>>>> CREATE TABLE `a``b` (`c"d` INT);
>>>>>>> Would you like update your patch? I think as optional callback 
>>>>>>> function ?
>>>>>>> Thanks,
>>>>>>> Alex
>>>>>>> Am 09.10.2009 um 16:27 schrieb Vincent CHAVANIS:
>>>>>>>>
>>>>>>>> this is Mysql specs (cf 
>>>>>>>> http://dev.mysql.com/doc/refman/5.0/en/identifiers.html)
>>>>>>>> eg. : A reserved word that follows a period in a qualified name 
>>>>>>>> must be an identifier, so it need not be quoted.
>>>>>>>>
>>>>>>>> Then, binds have absolutly nothing to do with this patch
>>>>>>>> I'm talking about field/table names specified on the config file.
>>>>>>>> But if binds are not escaped, then we need regular quotes is 
>>>>>>>> strings.
>>>>>>>>
>>>>>>>> Actually if you have a table/field names called SELECT or UPDATE 
>>>>>>>> or LIMIT or whatever reserved by mysql
>>>>>>>> then the SQL parsing error will occur. (And you have plenty of 
>>>>>>>> these, please check the link below)
>>>>>>>> (http://dev.mysql.com/doc/refman/5.0/en/reserved-words.html)
>>>>>>>>
>>>>>>>> Vincent.
>>>>>>>>
>>>> <mysql_table_quotes.patch>
>>
>> -- 
>> Telemaque - 06560 SOPHIA-ANTIPOLIS - (FR)
>> Service Technique/Reseau - NOC
>> Direction du Developpement xMS+
>> http://www.telemaque.fr/
>> [email protected]
>> Tel : +33 4 92 90 99 84 (fax 9142)
>>
> 
> 
> 

-- 
Telemaque - 06560 SOPHIA-ANTIPOLIS - (FR)
Service Technique/Reseau - NOC
Direction du Developpement xMS+
http://www.telemaque.fr/
[email protected]
Tel : +33 4 92 90 99 84 (fax 9142)
mysql_table_quotes.patch (text/plain, 3.3 KB)
--- dlr_mysql.c 2009-09-04 09:59:31.000000000 +0200
+++ dlr_mysql.c 2009-10-09 15:02:03.032683139 +0200
@@ -103,7 +103,7 @@
         return;
     }
 
-    sql = octstr_format("INSERT INTO %S (%S, %S, %S, %S, %S, %S, %S, %S, %S) VALUES "
+    sql = octstr_format("INSERT INTO `%S` (`%S`, `%S`, `%S`, `%S`, `%S`, `%S`, `%S`, `%S`, `%S`) VALUES "
                         "(?, ?, ?, ?, ?, ?, ?, ?, 0)",
                         fields->table, fields->field_smsc, fields->field_ts,
                         fields->field_src, fields->field_dst, fields->field_serv,
@@ -144,7 +144,7 @@
     if (pconn == NULL) /* should not happens, but sure is sure */
         return NULL;
 
-    sql = octstr_format("SELECT %S, %S, %S, %S, %S, %S FROM %S WHERE %S=? AND %S=? LIMIT 1",
+    sql = octstr_format("SELECT `%S`, `%S`, `%S`, `%S`, `%S`, `%S` FROM `%S` WHERE `%S`=? AND `%S`=? LIMIT 1",
                         fields->field_mask, fields->field_serv,
                         fields->field_url, fields->field_src,
                         fields->field_dst, fields->field_boxc,
@@ -202,7 +202,7 @@
     if (pconn == NULL)
         return;
 
-    sql = octstr_format("DELETE FROM %S WHERE %S=? AND %S=? LIMIT 1",
+    sql = octstr_format("DELETE FROM `%S` WHERE `%S`=? AND `%S`=? LIMIT 1",
                         fields->table, fields->field_smsc,
                         fields->field_ts);
 
@@ -234,7 +234,7 @@
     if (pconn == NULL)
         return;
 
-    sql = octstr_format("UPDATE %S SET %S=? WHERE %S=? AND %S=? LIMIT 1",
+    sql = octstr_format("UPDATE `%S` SET `%S`=? WHERE `%S`=? AND `%S`=? LIMIT 1",
                         fields->table, fields->field_status,
                         fields->field_smsc, fields->field_ts);
 
@@ -267,7 +267,7 @@
     if (conn == NULL)
         return -1;
 
-    sql = octstr_format("SELECT count(*) FROM %S", fields->table);
+    sql = octstr_format("SELECT count(*) FROM `%S`", fields->table);
 #if defined(DLR_TRACE)
     debug("dlr.mysql", 0, "sql: %s", octstr_get_cstr(sql));
 #endif
@@ -301,7 +301,7 @@
     if (pconn == NULL)
         return;
 
-    sql = octstr_format("DELETE FROM %S", fields->table);
+    sql = octstr_format("DELETE FROM `%S`", fields->table);
 #if defined(DLR_TRACE)
     debug("dlr.mysql", 0, "sql: %s", octstr_get_cstr(sql));
 #endif

@@ -349,6 +347,20 @@
     gw_assert(fields != NULL);
 
     /*
+     * Escaping special quotes for field/table names
+     */
+    octstr_replace(fields->table, octstr_imm("`"), octstr_imm("``"));
+    octstr_replace(fields->field_smsc, octstr_imm("`"), octstr_imm("``"));
+    octstr_replace(fields->field_ts, octstr_imm("`"), octstr_imm("``"));
+    octstr_replace(fields->field_src, octstr_imm("`"), octstr_imm("``"));
+    octstr_replace(fields->field_dst, octstr_imm("`"), octstr_imm("``"));
+    octstr_replace(fields->field_serv, octstr_imm("`"), octstr_imm("``"));
+    octstr_replace(fields->field_url, octstr_imm("`"), octstr_imm("``"));
+    octstr_replace(fields->field_mask, octstr_imm("`"), octstr_imm("``"));
+    octstr_replace(fields->field_status, octstr_imm("`"), octstr_imm("``"));
+    octstr_replace(fields->field_boxc, octstr_imm("`"), octstr_imm("``"));
+
+    /*
      * now grap the required information from the 'mysql-connection' group
      * with the mysql-id we just obtained
      *
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.