summaryrefslogtreecommitdiffstats
path: root/src
diff options
context:
space:
mode:
authorOmar Roth <omarroth@protonmail.com>2019-07-09 09:34:19 -0500
committerOmar Roth <omarroth@protonmail.com>2019-07-09 09:34:19 -0500
commit99b0b4f5b8d912afe62e88301628ffc7540c5f83 (patch)
treed05c9943d06abe129bb36a6c38bc87b458c728db /src
parentbcd239ac2b438ec721ffe35868371a9c81573f0a (diff)
downloadinvidious-99b0b4f5b8d912afe62e88301628ffc7540c5f83.tar.gz
invidious-99b0b4f5b8d912afe62e88301628ffc7540c5f83.tar.bz2
invidious-99b0b4f5b8d912afe62e88301628ffc7540c5f83.zip
Fix escaping for materialized view SQL
Diffstat (limited to 'src')
-rw-r--r--src/invidious/users.cr2
1 files changed, 1 insertions, 1 deletions
diff --git a/src/invidious/users.cr b/src/invidious/users.cr
index c988c0c4..1b5d34c6 100644
--- a/src/invidious/users.cr
+++ b/src/invidious/users.cr
@@ -1,7 +1,7 @@
require "crypto/bcrypt/password"
# Materialized views may not be defined using bound parameters (`$1` as used elsewhere)
-MATERIALIZED_VIEW_SQL = ->(email : String) { "SELECT cv.* FROM channel_videos cv WHERE EXISTS (SELECT subscriptions FROM users u WHERE cv.ucid = ANY (u.subscriptions) AND u.email = E'#{email.gsub("'", "\\'")}') ORDER BY published DESC" }
+MATERIALIZED_VIEW_SQL = ->(email : String) { "SELECT cv.* FROM channel_videos cv WHERE EXISTS (SELECT subscriptions FROM users u WHERE cv.ucid = ANY (u.subscriptions) AND u.email = E'#{email.gsub({'\'' => "\\'", '\\' => "\\\\"})}') ORDER BY published DESC" }
struct User
module PreferencesConverter