From e17e002b6902094d5811d0669313e67d96bb6ca4 Mon Sep 17 00:00:00 2001
From: alex <alex@alexloehr.net>
Date: Thu, 05 Jun 2025 09:19:00 +0000
Subject: [PATCH] fixed user by login
---
lib/db.js | 8 ++------
1 files changed, 2 insertions(+), 6 deletions(-)
diff --git a/lib/db.js b/lib/db.js
index af7a8e6..8355623 100644
--- a/lib/db.js
+++ b/lib/db.js
@@ -78,30 +78,26 @@
async function getUserByLogin (login) {
const sel = `usr_id, login, firstname, lastname, gender, email, institution, street, city, zipcode, country, department, active`
- // TODO user defined fields
// TODO check args for SQL Injection
const pool = await poolP
const [results, fields] = await pool.query(
`SELECT ${sel}
FROM ${database}.usr_data AS ud
- WHERE login = '${login}'
- AND login REGEXP '^[0-9]+$'`
+ WHERE login = '${login}'`
)
return joinUDF(results[0])
}
async function getUserByUserId (userId) {
const sel = `usr_id, login, firstname, lastname, gender, email, institution, street, city, zipcode, country, department, active`
- // TODO user defined fields
// TODO check args for SQL Injection
const pool = await poolP
const [results, fields] = await pool.query(
`SELECT ${sel}
FROM ${database}.usr_data AS ud
- WHERE usr_id = '${userId}'
- AND login REGEXP '^[0-9]+$'`
+ WHERE usr_id = '${userId}'`
)
return joinUDF(results[0])
}
--
Gitblit v1.8.0