diff options
author | Unknwon <joe2010xtmf@163.com> | 2014-11-04 11:37:15 -0500 |
---|---|---|
committer | Unknwon <joe2010xtmf@163.com> | 2014-11-04 11:37:15 -0500 |
commit | 0c5ba4573aecc9eaed669e9431a70a5d9f184b8d (patch) | |
tree | aaca06a83f8c6d827a728a9a672d53b7d2187464 /models | |
parent | 69a98236bdab4345c8b397a5a91f5e5abf745b42 (diff) | |
download | gitea-0c5ba4573aecc9eaed669e9431a70a5d9f184b8d.tar.gz gitea-0c5ba4573aecc9eaed669e9431a70a5d9f184b8d.zip |
fix session API broken and SQL pretection
Diffstat (limited to 'models')
-rw-r--r-- | models/repo.go | 2 | ||||
-rw-r--r-- | models/user.go | 2 |
2 files changed, 2 insertions, 2 deletions
diff --git a/models/repo.go b/models/repo.go index 888dea1ea6..37cc7eabf5 100644 --- a/models/repo.go +++ b/models/repo.go @@ -1161,7 +1161,7 @@ func SearchRepositoryByName(opt SearchOption) (repos []*Repository, err error) { if !opt.Private { sess.And("is_private=false") } - sess.And("lower_name like '%" + opt.Keyword + "%'").Find(&repos) + sess.And("lower_name like ?", "%"+opt.Keyword+"%").Find(&repos) return repos, err } diff --git a/models/user.go b/models/user.go index ce85008ba4..e7e6ed409f 100644 --- a/models/user.go +++ b/models/user.go @@ -581,7 +581,7 @@ func SearchUserByName(opt SearchOption) (us []*User, err error) { opt.Keyword = strings.ToLower(opt.Keyword) us = make([]*User, 0, opt.Limit) - err = x.Limit(opt.Limit).Where("type=0").And("lower_name like '%" + opt.Keyword + "%'").Find(&us) + err = x.Limit(opt.Limit).Where("type=0").And("lower_name like ?", "%"+opt.Keyword+"%").Find(&us) return us, err } |