]> git.decadent.org.uk Git - dak.git/blobdiff - daklib/database.py
escape strings for comments on packages and comment authors
[dak.git] / daklib / database.py
index a52555682624ca8aac8fa693acac8f805eb797f4..0be839b65cb5db0adbd0a8b2baf31878af0f1032 100755 (executable)
@@ -907,7 +907,7 @@ def add_new_comment(package, version, comment, author):
 
     projectB.query(""" INSERT INTO new_comments (package, version, comment, author)
                        VALUES ('%s', '%s', '%s', '%s')
-    """ % (package, version, comment, author) )
+    """ % (package, version, pg.escape_string(comment), pg.escape_string(author)))
 
     return