Merge pull request #12969 from surajshetty3416/fix-sqli-report-get

This commit is contained in:
Suraj Shetty 2021-05-12 12:57:17 +05:30 committed by GitHub
commit 0f94407e6d
No known key found for this signature in database
GPG key ID: 4AEE18F83AFDEB23

View file

@ -1278,7 +1278,9 @@ def make_filter_dict(filters):
def sanitize_column(column_name):
from frappe import _
import sqlparse
regex = re.compile("^.*[,'();].*")
column_name = sqlparse.format(column_name, strip_comments=True, keyword_case="lower")
blacklisted_keywords = ['select', 'create', 'insert', 'delete', 'drop', 'update', 'case', 'and', 'or']
def _raise_exception():