[mythtv-commits] Ticket #3072: MythGame: Apostrophe or single quote in filename breaks selection.

MythTV mythtv at cvs.mythtv.org
Wed Nov 7 19:47:15 UTC 2007

#3072: MythGame: Apostrophe or single quote in filename breaks selection.
 Reporter:  spikeygg at gmail.com  |        Owner:  greg    
     Type:  defect              |       Status:  reopened
 Priority:  minor               |    Milestone:  unknown 
Component:  mythgame            |      Version:  0.20    
 Severity:  medium              |   Resolution:          
  Mlocked:  0                   |  

Comment(by mythtv at pasher.org):

 I think it's obvious from your snide comments that you are nothing more
 than a troll trying to stir up trouble. It also shows you really don't
 understand the problem at hand.

 Back on topic, the sample code change that was posted to illustrate a fix
 (but not necessarily the most ideal fix) is dealing with a field in the
 database that is completely separate from the filename. The romname field
 of gamemetadata holds the filename, while the gamename field holds the
 name of the game to display in the selection list. They can be changed
 independently of each other. Does this mean you are saying we should stop
 using all of the "idiot or moron" characters when giving a friendly
 display name for our data too?

 There are other SQL statements that do pull information based upon on the
 romname (which does equate to the filename), but that doesn't mean they
 should not be fixed. This is no different than someone implementing SQL
 injection protection on a web site, in the event that the programmer
 cannot make any guaranteed judgments about the safety of the input.

Ticket URL: <http://svn.mythtv.org/trac/ticket/3072#comment:9>
MythTV <http://svn.mythtv.org/trac>

More information about the mythtv-commits mailing list