Project

General

Profile

Actions

Bug #6203

closed

Error handling username with single quote in Captive Portal SQL Database

Added by Phillip Davis over 5 years ago. Updated over 5 years ago.

Status:
Resolved
Priority:
Normal
Assignee:
Category:
Captive Portal
Target version:
Start date:
04/19/2016
Due date:
% Done:

0%

Estimated time:
Plus Target Version:
Release Notes:
Affected Version:
2.3
Affected Architecture:

Description

Forum: https://forum.pfsense.org/index.php?topic=110243.0

Single quotes in user names need to be escaped as 2 single quotes in order to insert them as string literals in SQL statements.

I suspect this was also a problem in older versions prior to 2.3, but for whatever reason did not cause a "crash"report.

Actions #2

Updated by Phillip Davis over 5 years ago

And PR has already been merged while I was typing the redmine issue!

Actions #3

Updated by Steve Beaver over 5 years ago

  • Status changed from New to Feedback
Actions #4

Updated by Chris Buechler over 5 years ago

  • Status changed from Feedback to Resolved

works, thanks Phil

Actions

Also available in: Atom PDF