From bada8cabcbfaafee44be212ff5896a8985cd50dd Mon Sep 17 00:00:00 2001 From: Akhil Narang Date: Fri, 7 Mar 2025 16:57:27 +0530 Subject: [PATCH] fix(db_query): improve regex Signed-off-by: Akhil Narang --- frappe/model/db_query.py | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/frappe/model/db_query.py b/frappe/model/db_query.py index 333e494ef1..113b68257b 100644 --- a/frappe/model/db_query.py +++ b/frappe/model/db_query.py @@ -42,7 +42,7 @@ SUB_QUERY_PATTERN = re.compile("^.*[,();@].*") IS_QUERY_PATTERN = re.compile(r"^(select|delete|update|drop|create)\s") IS_QUERY_PREDICATE_PATTERN = re.compile(r"\s*[0-9a-zA-z]*\s*( from | group by | order by | where | join )") FIELD_QUOTE_PATTERN = re.compile(r"[0-9a-zA-Z]+\s*'") -FIELD_COMMA_PATTERN = re.compile(r"[0-9a-zA-Z]+\s*,") +FIELD_COMMA_PATTERN = re.compile(r"[0-9a-zA-Z_]+\s*,") STRICT_FIELD_PATTERN = re.compile(r".*/\*.*") STRICT_UNION_PATTERN = re.compile(r".*\s(union).*\s") ORDER_GROUP_PATTERN = re.compile(r".*[^a-z0-9-_ ,`'\"\.\(\)].*")