Skip to content
This repository

HTTPS clone URL

Subversion checkout URL

You can clone with HTTPS or Subversion.

Download ZIP
Browse code

Fix stupid not exists omission

  • Loading branch information...
commit af75bd59f0629a3a8533b8e8cb2691289f49abe4 1 parent 64b9e43
Peter Rabbitson ribasushi authored
2  Changes
... ... @@ -1,5 +1,7 @@
1 1 Revision history for SQL::Abstract
2 2
  3 + - Fix parsing of NOT EXISTS
  4 +
3 5 revision 1.72 2010-12-21
4 6 ----------------------------
5 7 - Extra checks of search arguments for possible SQL injection attacks
6 lib/SQL/Abstract/Tree.pm
@@ -64,7 +64,7 @@ my @expression_start_keywords = (
64 64 'ON',
65 65 'WHERE',
66 66 '(?: DEFAULT \s+ )? VALUES',
67   - 'EXISTS',
  67 + '(?:NOT \s+)? EXISTS',
68 68 'GROUP \s+ BY',
69 69 'HAVING',
70 70 'ORDER \s+ BY',
@@ -379,8 +379,8 @@ sub _recurse_parse {
379 379 elsif ( $token =~ /^ NOT $/ix ) {
380 380 my $op = uc $token;
381 381 my $right = $self->_recurse_parse ($tokens, PARSE_RHS);
382   - $left = $left ? [ @$left, [$op => [$right] ]]
383   - : [ $op => [$right] ];
  382 + $left = $left ? [ @$left, [$op => [$right||()] ]]
  383 + : [ $op => [$right||()] ];
384 384
385 385 }
386 386 elsif ( $token =~ $placeholder_re) {
1  t/14roundtrippin.t
@@ -14,6 +14,7 @@ my @sql = (
14 14 "SELECT * FROM (SELECT * FROM foobar) WHERE foo.a = 1 and foo.b LIKE 'station'",
15 15 "SELECT * FROM lolz WHERE ( foo.a =1 ) and foo.b LIKE 'station'",
16 16 "SELECT [screen].[id], [screen].[name], [screen].[section_id], [screen].[xtype] FROM [users_roles] [me] JOIN [roles] [role] ON [role].[id] = [me].[role_id] JOIN [roles_permissions] [role_permissions] ON [role_permissions].[role_id] = [role].[id] JOIN [permissions] [permission] ON [permission].[id] = [role_permissions].[permission_id] JOIN [permissionscreens] [permission_screens] ON [permission_screens].[permission_id] = [permission].[id] JOIN [screens] [screen] ON [screen].[id] = [permission_screens].[screen_id] WHERE ( [me].[user_id] = ? ) GROUP BY [screen].[id], [screen].[name], [screen].[section_id], [screen].[xtype]",
  17 + "SELECT * FROM foo WHERE NOT EXISTS (SELECT bar FROM baz)",
17 18 );
18 19
19 20 for (@sql) {

0 comments on commit af75bd5

Please sign in to comment.
Something went wrong with that request. Please try again.