[mythtv-commits] Ticket #3072: MythGame: Apostrophe or single quote in filename breaks selection.
MythTV
mythtv at cvs.mythtv.org
Wed Nov 7 19:47:15 UTC 2007
#3072: MythGame: Apostrophe or single quote in filename breaks selection.
--------------------------------+-------------------------------------------
Reporter: spikeygg at gmail.com | Owner: greg
Type: defect | Status: reopened
Priority: minor | Milestone: unknown
Component: mythgame | Version: 0.20
Severity: medium | Resolution:
Mlocked: 0 |
--------------------------------+-------------------------------------------
Comment(by mythtv at pasher.org):
I think it's obvious from your snide comments that you are nothing more
than a troll trying to stir up trouble. It also shows you really don't
understand the problem at hand.
Back on topic, the sample code change that was posted to illustrate a fix
(but not necessarily the most ideal fix) is dealing with a field in the
database that is completely separate from the filename. The romname field
of gamemetadata holds the filename, while the gamename field holds the
name of the game to display in the selection list. They can be changed
independently of each other. Does this mean you are saying we should stop
using all of the "idiot or moron" characters when giving a friendly
display name for our data too?
There are other SQL statements that do pull information based upon on the
romname (which does equate to the filename), but that doesn't mean they
should not be fixed. This is no different than someone implementing SQL
injection protection on a web site, in the event that the programmer
cannot make any guaranteed judgments about the safety of the input.
--
Ticket URL: <http://svn.mythtv.org/trac/ticket/3072#comment:9>
MythTV <http://svn.mythtv.org/trac>
MythTV
More information about the mythtv-commits
mailing list