Skip to content
Snippets Groups Projects
Commit 0c716bcc authored by Fabien Zucchet's avatar Fabien Zucchet
Browse files

Try to fix SQL injections

parent 8e6fb934
Branches
No related tags found
No related merge requests found
const mysql = require('mysql'); const mysql = require('mysql');
const fetch = require('node-fetch'); const fetch = require('node-fetch');
const sql = require('../tools/sql.js')
var secrets = require('../secrets.js'); var secrets = require('../secrets.js');
var dbhost = secrets.dbhost; var dbhost = secrets.dbhost;
var dbuser = secrets.dbuser; var dbuser = secrets.dbuser;
...@@ -45,9 +44,10 @@ function addNewAdministrateur(req, res) { ...@@ -45,9 +44,10 @@ function addNewAdministrateur(req, res) {
function updateAdministrateur(req, res) { function updateAdministrateur(req, res) {
var con = mysql.createConnection(dbConfig); var con = mysql.createConnection(dbConfig);
var query = "UPDATE Admin SET login = '" + req.body.login + "' WHERE id=" + req.body.id + ";" var query = "UPDATE Admin SET login = ? WHERE id=?;"
var inserts = [req.body.login, req.body.id];
con.connect(); con.connect();
con.query(query, (err, result) => { con.query(query, inserts, (err, result) => {
if (err) { if (err) {
console.log(err) console.log(err)
return res.send({ success: false }) return res.send({ success: false })
......
exports.preparer = function (mysql, requete_sql, inserts) {
requete_sql = mysql.format(requete_sql, inserts)
// nous utilisons la méthode .remplace avec une expression régulière
// pour supprimer les accents graves et les points
.replace(/`/g, "'")
.replace(/'\.'/g, ".")
.replace(/'/g, "\\'");
return requete_sql;
}
\ No newline at end of file
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Please register or to comment