FIXED SQL INJECTION
This commit is contained in:
@@ -406,8 +406,10 @@ def search_artworks(query: str) -> List[Dict]:
|
|||||||
conn = get_db()
|
conn = get_db()
|
||||||
c = conn.cursor()
|
c = conn.cursor()
|
||||||
try:
|
try:
|
||||||
search_query = f"SELECT * FROM artworks WHERE title LIKE '%{query}%' OR data LIKE '%{query}%'"
|
c.execute(
|
||||||
c.execute(search_query)
|
"SELECT * FROM artworks WHERE title LIKE ? OR data LIKE ?",
|
||||||
|
(f"%{query}%", f"%{query}%")
|
||||||
|
)
|
||||||
results_data = c.fetchall()
|
results_data = c.fetchall()
|
||||||
return [
|
return [
|
||||||
{
|
{
|
||||||
|
|||||||
Reference in New Issue
Block a user