changeset f169c518cd8d in /home/hg/repos/gajim
details:http://hg.gajim.org/gajim?cmd=changeset;node=f169c518cd8d
description: replace all %d / %s things in SQL queries by ? for security reasons
diffstat:
src/common/logger.py | 81 ++++++++++++++++++++--------------------
1 files changed, 40 insertions(+), 41 deletions(-)
diffs (185 lines):
diff -r 680037f23ca5 -r f169c518cd8d src/common/logger.py
--- a/src/common/logger.py Sat Oct 31 23:22:12 2009 +0100
+++ b/src/common/logger.py Sat Oct 31 23:57:14 2009 +0100
@@ -149,9 +149,12 @@
self.open_db()
self.get_jids_already_in_db()
- def simple_commit(self, sql_to_commit):
+ def simple_commit(self, sql_to_commit, values=None):
'''helper to commit'''
- self.cur.execute(sql_to_commit)
+ if values:
+ self.cur.execute(sql_to_commit, values)
+ else:
+ self.cur.execute(sql_to_commit)
try:
self.con.commit()
except sqlite.OperationalError, e:
@@ -383,21 +386,19 @@
def insert_unread_events(self, message_id, jid_id):
''' add unread message with id: message_id'''
- sql = 'INSERT INTO unread_messages VALUES (%d, %d, 0)' % (message_id,
- jid_id)
- self.simple_commit(sql)
+ sql = 'INSERT INTO unread_messages VALUES (?, ?, 0)'
+ self.simple_commit(sql, values=(message_id, jid_id))
def set_read_messages(self, message_ids):
''' mark all messages with ids in message_ids as read'''
ids = ','.join([str(i) for i in message_ids])
- sql = 'DELETE FROM unread_messages WHERE message_id IN (%s)' % ids
- self.simple_commit(sql)
+ sql = 'DELETE FROM unread_messages WHERE message_id IN (?)'
+ self.simple_commit(sql, values=(ids,))
def set_shown_unread_msgs(self, msg_id):
''' mark unread message as shown un GUI '''
- sql = 'UPDATE unread_messages SET shown = 1 where message_id = %s' % \
- msg_id
- self.simple_commit(sql)
+ sql = 'UPDATE unread_messages SET shown = 1 where message_id = ?'
+ self.simple_commit(sql, values=(msg_id,))
def reset_shown_unread_messages(self):
''' Set shown field to False in unread_messages table '''
@@ -423,8 +424,8 @@
SELECT logs.log_line_id, logs.message, logs.time, logs.subject,
jids.jid
FROM logs, jids
- WHERE logs.log_line_id = %d AND logs.jid_id = jids.jid_id
- ''' % msg_id
+ WHERE logs.log_line_id = ? AND logs.jid_id = jids.jid_id
+ ''', (msg_id,)
)
results = self.cur.fetchall()
if len(results) == 0:
@@ -536,9 +537,9 @@
try:
self.cur.execute('''
SELECT time, kind, message FROM logs
- WHERE (%s) AND kind IN (%d, %d, %d, %d, %d) AND time > %d
- ORDER BY time DESC LIMIT %d OFFSET %d
- ''' % (where_sql, constants.KIND_SINGLE_MSG_RECV,
+ WHERE (?) AND kind IN (?, ?, ?, ?, ?) AND time > ?
+ ORDER BY time DESC LIMIT ? OFFSET ?
+ ''', (where_sql, constants.KIND_SINGLE_MSG_RECV,
constants.KIND_CHAT_MSG_RECV, constants.KIND_SINGLE_MSG_SENT,
constants.KIND_CHAT_MSG_SENT, constants.KIND_ERROR,
timed_out, restore_how_many_rows, pending_how_many)
@@ -577,10 +578,10 @@
self.cur.execute('''
SELECT contact_name, time, kind, show, message, subject FROM logs
- WHERE (%s)
- AND time BETWEEN %d AND %d
+ WHERE (?)
+ AND time BETWEEN ? AND ?
ORDER BY time
- ''' % (where_sql, start_of_day, last_second_of_day))
+ ''', (where_sql, start_of_day, last_second_of_day))
results = self.cur.fetchall()
return results
@@ -607,9 +608,9 @@
like_sql = '%' + query.replace("'", "''") + '%'
self.cur.execute('''
SELECT contact_name, time, kind, show, message, subject FROM logs
- WHERE (%s) AND message LIKE '%s'
+ WHERE (?) AND message LIKE '?'
ORDER BY time
- ''' % (where_sql, like_sql))
+ ''', (where_sql, like_sql))
results = self.cur.fetchall()
return results
@@ -635,11 +636,11 @@
# Now we have timestamps of time 0:00 of every day with logs
self.cur.execute('''
SELECT DISTINCT time/(86400)*86400 FROM logs
- WHERE (%s)
- AND time BETWEEN %d AND %d
- AND kind NOT IN (%d, %d)
+ WHERE (?)
+ AND time BETWEEN ? AND ?
+ AND kind NOT IN (?, ?)
ORDER BY time
- ''' % (where_sql, start_of_month, last_second_of_month,
+ ''', (where_sql, start_of_month, last_second_of_month,
constants.KIND_STATUS, constants.KIND_GCSTATUS))
result = self.cur.fetchall()
@@ -664,9 +665,9 @@
where_sql = 'jid_id = %s' % jid_id
self.cur.execute('''
SELECT MAX(time) FROM logs
- WHERE (%s)
- AND kind NOT IN (%d, %d)
- ''' % (where_sql, constants.KIND_STATUS, constants.KIND_GCSTATUS))
+ WHERE (?)
+ AND kind NOT IN (?, ?)
+ ''', (where_sql, constants.KIND_STATUS, constants.KIND_GCSTATUS))
results = self.cur.fetchone()
if results is not None:
@@ -686,8 +687,8 @@
where_sql = 'jid_id = %s' % jid_id
self.cur.execute('''
SELECT time FROM rooms_last_message_time
- WHERE (%s)
- ''' % (where_sql))
+ WHERE (?)
+ ''', (where_sql,))
results = self.cur.fetchone()
if results is not None:
@@ -701,9 +702,8 @@
we had logs for that room in rooms_last_message_time table'''
jid_id = self.get_jid_id(jid, 'ROOM')
# jid_id is unique in this table, create or update :
- sql = 'REPLACE INTO rooms_last_message_time VALUES (%d, %d)' % \
- (jid_id, time)
- self.simple_commit(sql)
+ sql = 'REPLACE INTO rooms_last_message_time VALUES (?, ?)'
+ self.simple_commit(sql, (jid_id, time))
def _build_contact_where(self, account, jid):
'''build the where clause for a jid, including metacontacts
@@ -733,18 +733,17 @@
# unknown type
return
self.cur.execute(
- 'SELECT type from transports_cache WHERE transport = "%s"' % jid)
+ 'SELECT type from transports_cache WHERE transport = "?"', (jid,))
results = self.cur.fetchall()
if results:
result = results[0][0]
if result == type_id:
return
- sql = 'UPDATE transports_cache SET type = %d WHERE transport = "%s"' %\
- (type_id, jid)
- self.simple_commit(sql)
+ sql = 'UPDATE transports_cache SET type = ? WHERE transport = "?"'
+ self.simple_commit(sql, values=(type_id, jid))
return
- sql = 'INSERT INTO transports_cache VALUES ("%s", %d)' % (jid, type_id)
- self.simple_commit(sql)
+ sql = 'INSERT INTO transports_cache VALUES ("?", ?)'
+ self.simple_commit(sql, values=(jid, type_id))
def get_transports_type(self):
'''return all the type of the transports in DB'''
@@ -815,9 +814,9 @@
# yield the row
yield hash_method, hash_, identities, features
for hash_method, hash_ in to_be_removed:
- sql = '''DELETE FROM caps_cache WHERE hash_method = "%s" AND
- hash = "%s"''' % (hash_method, hash_)
- self.simple_commit(sql)
+ sql = '''DELETE FROM caps_cache WHERE hash_method = "?" AND
+ hash = "?"'''
+ self.simple_commit(sql, values=(hash_method, hash_))
def add_caps_entry(self, hash_method, hash_, identities, features):
data = []
changeset 680037f23ca5 in /home/hg/repos/gajim
details:http://hg.gajim.org/gajim?cmd=changeset;node=680037f23ca5
description: ignore unknown show types when we receive strange stanza.
diffstat:
src/common/connection_handlers.py | 2 +-
1 files changed, 1 insertions(+), 1 deletions(-)
diffs (12 lines):
diff -r 2aeef7498c6d -r 680037f23ca5 src/common/connection_handlers.py
--- a/src/common/connection_handlers.py Sat Oct 31 22:57:14 2009 +0100
+++ b/src/common/connection_handlers.py Sat Oct 31 23:22:12 2009 +0100
@@ -2259,7 +2259,7 @@
is_gc = True
status = prs.getStatus() or ''
show = prs.getShow()
- if not show in gajim.SHOW_LIST:
+ if show not in ('chat', 'away', 'xa', 'dnd'):
show = '' # We ignore unknown show
if not ptype and not show:
show = 'online'
changeset b1e34857211d in /home/hg/repos/gajim
details:http://hg.gajim.org/gajim?cmd=changeset;node=b1e34857211d
description: [Mattj] improve join groupchat behaviour. Fixes #5383
diffstat:
src/conversation_textview.py | 2 +-
src/dialogs.py | 38 ++++++++++++++++++++++----------------
2 files changed, 23 insertions(+), 17 deletions(-)
diffs (67 lines):
diff -r d5afbd93ca80 -r b1e34857211d src/conversation_textview.py
--- a/src/conversation_textview.py Sat Oct 31 19:15:18 2009 +0100
+++ b/src/conversation_textview.py Sat Oct 31 19:35:46 2009 +0100
@@ -853,7 +853,7 @@
gajim.interface.instances[self.account]['join_gc'].window.present()
else:
try:
- dialogs.JoinGroupchatWindow(account=None, room_jid=room_jid)
+ dialogs.JoinGroupchatWindow(account=self.account, room_jid=room_jid)
except GajimGeneralException:
pass
diff -r d5afbd93ca80 -r b1e34857211d src/dialogs.py
--- a/src/dialogs.py Sat Oct 31 19:15:18 2009 +0100
+++ b/src/dialogs.py Sat Oct 31 19:35:46 2009 +0100
@@ -1922,7 +1922,7 @@
'''automatic is a dict like {'invities': []}
If automatic is not empty, this means room must be automaticaly configured
and when done, invities must be automatically invited'''
- self.xml = gtkgui_helpers.get_glade('join_groupchat_window.glade')
+
if account:
if room_jid != '' and room_jid in gajim.gc_connected[account] and\
gajim.gc_connected[account][room_jid]:
@@ -1934,21 +1934,27 @@
ErrorDialog(_('You are not connected to the server'),
_('You can not join a group chat unless you are connected.'))
raise GajimGeneralException, 'You must be connected to join a groupchat'
- else:
- account_label = self.xml.get_widget('account_label')
- account_combobox = self.xml.get_widget('account_combobox')
- account_label.set_no_show_all(False)
- account_combobox.set_no_show_all(False)
- liststore = gtk.ListStore(str)
- account_combobox.set_model(liststore)
- cell = gtk.CellRendererText()
- account_combobox.pack_start(cell, True)
- account_combobox.add_attribute(cell, 'text', 0)
- for acct in [a for a in gajim.connections if \
- gajim.account_is_connected(a)]:
- account_combobox.append_text(acct)
- account_combobox.set_active(-1)
-
+
+ self.xml = gtkgui_helpers.get_glade('join_groupchat_window.glade')
+
+ account_label = self.xml.get_widget('account_label')
+ account_combobox = self.xml.get_widget('account_combobox')
+ account_label.set_no_show_all(False)
+ account_combobox.set_no_show_all(False)
+ liststore = gtk.ListStore(str)
+ account_combobox.set_model(liststore)
+ cell = gtk.CellRendererText()
+ account_combobox.pack_start(cell, True)
+ account_combobox.add_attribute(cell, 'text', 0)
+ account_combobox.set_active(-1)
+
+ # Add accounts, set current as active if it matches 'account'
+ for acct in [a for a in gajim.connections if \
+ gajim.account_is_connected(a)]:
+ account_combobox.append_text(acct)
+ if account and account == acct:
+ account_combobox.set_active(liststore.iter_n_children(None)-1)
+
self.account = account
self.automatic = automatic
self._empty_required_widgets = []