Re: [PATCH] dlr_mysql.c - Table name fix
Vincent CHAVANIS <[email protected]>
| Newsgroups | gmane.comp.mobile.kannel.devel |
|---|---|
| Message-ID | <[email protected]> |
Ok, attached the new patch here.
Vincent.
Alexander Malysh a écrit :
>
> Am 13.10.2009 um 00:09 schrieb Vincent CHAVANIS:
>
>>
>> I'm sure we will find other specific cases that will be processed into
>> this function ;)
>> Let it as it.
>
> Vincent, sorry but I don't see reason and case that we will add there.
> Please consider to kill function call
> or show me another functional line in this function...
>
> We always can easy add this function again if we find any case that we
> have to escape...
>
>>
>> Vincent.
>>
>>
>> Alexander Malysh a écrit :
>>> hmm, you make it tooo complicated ;)
>>> why not just:
>>> octstr_replace(fields->table, octstr_imm("`"), octstr_imm("``"));
>>> ...
>>> instead of calling function/macro with only one line?
>>> Thanks,
>>> Alex
>>> Am 12.10.2009 um 13:45 schrieb Vincent CHAVANIS:
>>>>
>>>> done.
>>>>
>>>> Vincent
>>>>
>>>>
>>>> Alexander Malysh a écrit :
>>>>> Hi again,
>>>>> I don't see reason to use macro because macro contains only one
>>>>> line...
>>>>> Could you please drop macro and use plain function call?
>>>>> Thanks,
>>>>> Alex
>>>>> Am 12.10.2009 um 12:39 schrieb Vincent CHAVANIS:
>>>>>>
>>>>>> Damn! you're right ;-)
>>>>>>
>>>>>> For this issue, i decided to use a macro that
>>>>>> replaces names during the init process
>>>>>>
>>>>>> Comments ?
>>>>>>
>>>>>> Vincent.
>>>>>>
>>>>>>
>>>>>> Alexander Malysh a écrit :
>>>>>>> Hi,
>>>>>>> +1 for this patch but patch is not complete. It doesn't handle
>>>>>>> this case:
>>>>>>> CREATE TABLE `a``b` (`c"d` INT);
>>>>>>> Would you like update your patch? I think as optional callback
>>>>>>> function ?
>>>>>>> Thanks,
>>>>>>> Alex
>>>>>>> Am 09.10.2009 um 16:27 schrieb Vincent CHAVANIS:
>>>>>>>>
>>>>>>>> this is Mysql specs (cf
>>>>>>>> http://dev.mysql.com/doc/refman/5.0/en/identifiers.html)
>>>>>>>> eg. : A reserved word that follows a period in a qualified name
>>>>>>>> must be an identifier, so it need not be quoted.
>>>>>>>>
>>>>>>>> Then, binds have absolutly nothing to do with this patch
>>>>>>>> I'm talking about field/table names specified on the config file.
>>>>>>>> But if binds are not escaped, then we need regular quotes is
>>>>>>>> strings.
>>>>>>>>
>>>>>>>> Actually if you have a table/field names called SELECT or UPDATE
>>>>>>>> or LIMIT or whatever reserved by mysql
>>>>>>>> then the SQL parsing error will occur. (And you have plenty of
>>>>>>>> these, please check the link below)
>>>>>>>> (http://dev.mysql.com/doc/refman/5.0/en/reserved-words.html)
>>>>>>>>
>>>>>>>> Vincent.
>>>>>>>>
>>>> <mysql_table_quotes.patch>
>>
>> --
>> Telemaque - 06560 SOPHIA-ANTIPOLIS - (FR)
>> Service Technique/Reseau - NOC
>> Direction du Developpement xMS+
>> http://www.telemaque.fr/
>> [email protected]
>> Tel : +33 4 92 90 99 84 (fax 9142)
>>
>
>
>
--
Telemaque - 06560 SOPHIA-ANTIPOLIS - (FR)
Service Technique/Reseau - NOC
Direction du Developpement xMS+
http://www.telemaque.fr/
[email protected]
Tel : +33 4 92 90 99 84 (fax 9142)
mysql_table_quotes.patch
(text/plain, 3.3 KB)
--- dlr_mysql.c 2009-09-04 09:59:31.000000000 +0200
+++ dlr_mysql.c 2009-10-09 15:02:03.032683139 +0200
@@ -103,7 +103,7 @@
return;
}
- sql = octstr_format("INSERT INTO %S (%S, %S, %S, %S, %S, %S, %S, %S, %S) VALUES "
+ sql = octstr_format("INSERT INTO `%S` (`%S`, `%S`, `%S`, `%S`, `%S`, `%S`, `%S`, `%S`, `%S`) VALUES "
"(?, ?, ?, ?, ?, ?, ?, ?, 0)",
fields->table, fields->field_smsc, fields->field_ts,
fields->field_src, fields->field_dst, fields->field_serv,
@@ -144,7 +144,7 @@
if (pconn == NULL) /* should not happens, but sure is sure */
return NULL;
- sql = octstr_format("SELECT %S, %S, %S, %S, %S, %S FROM %S WHERE %S=? AND %S=? LIMIT 1",
+ sql = octstr_format("SELECT `%S`, `%S`, `%S`, `%S`, `%S`, `%S` FROM `%S` WHERE `%S`=? AND `%S`=? LIMIT 1",
fields->field_mask, fields->field_serv,
fields->field_url, fields->field_src,
fields->field_dst, fields->field_boxc,
@@ -202,7 +202,7 @@
if (pconn == NULL)
return;
- sql = octstr_format("DELETE FROM %S WHERE %S=? AND %S=? LIMIT 1",
+ sql = octstr_format("DELETE FROM `%S` WHERE `%S`=? AND `%S`=? LIMIT 1",
fields->table, fields->field_smsc,
fields->field_ts);
@@ -234,7 +234,7 @@
if (pconn == NULL)
return;
- sql = octstr_format("UPDATE %S SET %S=? WHERE %S=? AND %S=? LIMIT 1",
+ sql = octstr_format("UPDATE `%S` SET `%S`=? WHERE `%S`=? AND `%S`=? LIMIT 1",
fields->table, fields->field_status,
fields->field_smsc, fields->field_ts);
@@ -267,7 +267,7 @@
if (conn == NULL)
return -1;
- sql = octstr_format("SELECT count(*) FROM %S", fields->table);
+ sql = octstr_format("SELECT count(*) FROM `%S`", fields->table);
#if defined(DLR_TRACE)
debug("dlr.mysql", 0, "sql: %s", octstr_get_cstr(sql));
#endif
@@ -301,7 +301,7 @@
if (pconn == NULL)
return;
- sql = octstr_format("DELETE FROM %S", fields->table);
+ sql = octstr_format("DELETE FROM `%S`", fields->table);
#if defined(DLR_TRACE)
debug("dlr.mysql", 0, "sql: %s", octstr_get_cstr(sql));
#endif
@@ -349,6 +347,20 @@
gw_assert(fields != NULL);
/*
+ * Escaping special quotes for field/table names
+ */
+ octstr_replace(fields->table, octstr_imm("`"), octstr_imm("``"));
+ octstr_replace(fields->field_smsc, octstr_imm("`"), octstr_imm("``"));
+ octstr_replace(fields->field_ts, octstr_imm("`"), octstr_imm("``"));
+ octstr_replace(fields->field_src, octstr_imm("`"), octstr_imm("``"));
+ octstr_replace(fields->field_dst, octstr_imm("`"), octstr_imm("``"));
+ octstr_replace(fields->field_serv, octstr_imm("`"), octstr_imm("``"));
+ octstr_replace(fields->field_url, octstr_imm("`"), octstr_imm("``"));
+ octstr_replace(fields->field_mask, octstr_imm("`"), octstr_imm("``"));
+ octstr_replace(fields->field_status, octstr_imm("`"), octstr_imm("``"));
+ octstr_replace(fields->field_boxc, octstr_imm("`"), octstr_imm("``"));
+
+ /*
* now grap the required information from the 'mysql-connection' group
* with the mysql-id we just obtained
*