refactor: clean up comments and improve SQL injection prevention in cadastro_jogos desktop XML
davinTI/jogos_matheus/pipeline/head There was a failure building this commit
davinTI/jogos_matheus/pipeline/head There was a failure building this commit
This commit is contained in:
@@ -116,11 +116,7 @@
|
||||
engine.getField("txfNotaMedia").setValue("");
|
||||
}
|
||||
|
||||
/*
|
||||
* Gerencia apenas os campos de negócio obrigatórios.
|
||||
* Os campos de ID (CODIGO) NÃO entram aqui, pois são
|
||||
* gerados automaticamente e ficariam vazios em uma inclusão.
|
||||
*/
|
||||
|
||||
function organizeRequiredFields(whichForm, isToRequest) {
|
||||
var fields = [];
|
||||
if(whichForm === "jogos"){
|
||||
@@ -276,7 +272,6 @@
|
||||
var sqlBase = "SELECT * FROM TB_MATHEUS_MEDEIROS_AVALIACOES ORDER BY CODIGO";
|
||||
var id_jogo = engine.getField("dbtJogos").getValue();
|
||||
if(id_jogo != null){
|
||||
/* Cast numérico para evitar injeção via concatenação */
|
||||
id_jogo = parseInt(id_jogo, 10);
|
||||
if(!isNaN(id_jogo)){
|
||||
sqlBase = "SELECT * FROM TB_MATHEUS_MEDEIROS_AVALIACOES WHERE ID_JOGO = " + id_jogo + " ORDER BY CODIGO";
|
||||
@@ -415,8 +410,6 @@
|
||||
var sqlBase = "SELECT J.CODIGO, J.TITULO, J.GENERO, J.ANO_LANCAMENTO, J.PRODUTORA, COALESCE(ROUND(AVG(A.NOTA), 2), 0) AS NOTA_MEDIA, J.DESCRICAO FROM TB_MATHEUS_MEDEIROS_JOGOS J LEFT JOIN TB_MATHEUS_MEDEIROS_AVALIACOES A ON J.CODIGO = A.ID_JOGO";
|
||||
|
||||
if (txfPesquisa) {
|
||||
/* Escapa aspas simples para mitigar SQL Injection.
|
||||
O ideal é usar bind/parâmetro do framework. */
|
||||
var safe = ("" + txfPesquisa).replace(/'/g, "''");
|
||||
sqlBase += " WHERE UPPER(J.TITULO) LIKE UPPER('%" + safe + "%')";
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user