Skip to content

Commit 7117a3b

Browse files
authored
Merge pull request #585 from sipcapture/alert-autofix-4
Fix code scanning alert no. 4: Database query built from user-controlled sources
2 parents 63f628d + a5e40a0 commit 7117a3b

File tree

1 file changed

+1
-4
lines changed

1 file changed

+1
-4
lines changed

data/service/user.go

Lines changed: 1 addition & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -69,11 +69,8 @@ func (us *UserService) IsAdmin(email string) (bool, error) {
6969
func (us *UserService) GetUserByUUID(GUID, UserName string) ([]*model.TableUser, int, error) {
7070

7171
var user []*model.TableUser
72-
var sqlWhere = make(map[string]interface{})
73-
74-
sqlWhere = map[string]interface{}{"username": UserName, "guid": GUID}
7572

76-
if err := us.Session.Debug().Table("users").Where(sqlWhere).Find(&user).Error; err != nil {
73+
if err := us.Session.Debug().Table("users").Where("username = ? AND guid = ?", UserName, GUID).Find(&user).Error; err != nil {
7774
return user, 0, err
7875
}
7976

0 commit comments

Comments
 (0)