-
- Downloads
[BIS-260] Fix SQL injections for custom queries.
Add support for backward compatible specifications of strings with '${code}' and '{${array}}'. Add support for simplified specification of PostgreSQL arrays with "=ANY({${myarray}})". Add support for overriding the parameter type as placeholder metadata like in: ${code::varchar}. This is necessary to get things working for Oracle as the Oracle JDBC driver does not support calling ParameterMetaData.getParameterType(). SVN: 27635
Showing
- openbis/source/java/ch/systemsx/cisd/openbis/plugin/query/server/DAO.java 146 additions, 6 deletions...ava/ch/systemsx/cisd/openbis/plugin/query/server/DAO.java
- openbis/sourceTest/java/ch/systemsx/cisd/openbis/plugin/query/server/DAOTest.java 51 additions, 1 deletion...ch/systemsx/cisd/openbis/plugin/query/server/DAOTest.java
Loading
Please register or sign in to comment