Skip to content

Commit

Permalink
🦄 refactor:Sanitize SQL queries #47
Browse files Browse the repository at this point in the history
  • Loading branch information
DNA-styx committed Jan 16, 2025
1 parent 130be58 commit 1d1acb3
Show file tree
Hide file tree
Showing 5 changed files with 17 additions and 17 deletions.
6 changes: 3 additions & 3 deletions web/pages/bans.php
Original file line number Diff line number Diff line change
Expand Up @@ -48,7 +48,7 @@
FROM
hlstats_Games
WHERE
hlstats_Games.code = '$game'
hlstats_Games.code = '" . valid_request($game, false) . "'
");

if ($db->num_rows() < 1) {
Expand Down Expand Up @@ -150,7 +150,7 @@
FROM
hlstats_Players
WHERE
hlstats_Players.game = '$game'
hlstats_Players.game = '" . valid_request($game, false) . "'
AND hlstats_Players.hideranking = 2
AND hlstats_Players.kills >= $minkills
");
Expand All @@ -175,7 +175,7 @@
FROM
hlstats_Players
WHERE
hlstats_Players.game = '$game'
hlstats_Players.game = '" . valid_request($game, false) . "'
AND hlstats_Players.hideranking = 2
AND hlstats_Players.kills >= $minkills
ORDER BY
Expand Down
6 changes: 3 additions & 3 deletions web/pages/clans.php
Original file line number Diff line number Diff line change
Expand Up @@ -48,7 +48,7 @@
FROM
hlstats_Games
WHERE
hlstats_Games.code = '$game'
hlstats_Games.code = '" . valid_request($game, false) . "'
");

if ($db->num_rows() < 1) {
Expand Down Expand Up @@ -152,7 +152,7 @@
hlstats_Clans,
hlstats_Players
WHERE
hlstats_Clans.game = '$game'
hlstats_Clans.game = '" . valid_request($game, false) . "'
AND hlstats_Clans.hidden <> 1
AND hlstats_Players.clan = hlstats_Clans.clanId
AND hlstats_Players.hideranking = 0
Expand Down Expand Up @@ -181,7 +181,7 @@
ON
hlstats_Players.clan = hlstats_Clans.clanId
WHERE
hlstats_Clans.game = '$game'
hlstats_Clans.game = '" . valid_request($game, false) . "'
AND hlstats_Clans.hidden <> 1
AND hlstats_Players.hideranking = 0
GROUP BY
Expand Down
2 changes: 1 addition & 1 deletion web/pages/dailyawardinfo.php
Original file line number Diff line number Diff line change
Expand Up @@ -62,7 +62,7 @@
$awardtype = $awarddata['awardType'];
$awardcode = $awarddata['code'];

$db->query("SELECT name FROM hlstats_Games WHERE code='$game'");
$db->query("SELECT name FROM hlstats_Games WHERE code='" . valid_request($game, false) . "'");
if ($db->num_rows() < 1) {
error("No such game '$game'.");
}
Expand Down
12 changes: 6 additions & 6 deletions web/pages/game.php
Original file line number Diff line number Diff line change
Expand Up @@ -41,7 +41,7 @@
}

require (PAGE_PATH . '/livestats.php');
$db->query("SELECT name FROM hlstats_Games WHERE code='$game'");
$db->query("SELECT name FROM hlstats_Games WHERE code='" . valid_request($game, false) . "'");
if ($db->num_rows() < 1) {
error("No such game '$game'.");
}
Expand All @@ -57,7 +57,7 @@
FROM
hlstats_Players
WHERE
game='$game'
game='" . valid_request($game, false) . "'
";
$result = $db->query($query);
list($total_players) = $db->fetch_row($result);
Expand Down Expand Up @@ -88,7 +88,7 @@
FROM
hlstats_Servers
WHERE
game='$game'
game='" . valid_request($game, false) . "'
";
$result = $db->query($query);
list($total_kills, $total_headshots, $total_servers) = $db->fetch_row($result);
Expand All @@ -99,7 +99,7 @@
FROM
hlstats_Trend
WHERE
game='$game'
game='" . valid_request($game, false) . "'
AND timestamp<=" . (time() - 86400) . "
ORDER BY
timestamp DESC LIMIT 0,1
Expand Down Expand Up @@ -132,7 +132,7 @@
FROM
hlstats_Servers
WHERE
game='$game'
game='" . valid_request($game, false) . "'
ORDER BY
sortorder, name, serverId
";
Expand Down Expand Up @@ -302,7 +302,7 @@
LEFT JOIN hlstats_Players ON
hlstats_Players.playerId = hlstats_Awards.d_winner_id
WHERE
hlstats_Awards.game='$game'
hlstats_Awards.game='" . valid_request($game, false) . "'
ORDER BY
hlstats_Awards.name
");
Expand Down
8 changes: 4 additions & 4 deletions web/pages/roles.php
Original file line number Diff line number Diff line change
Expand Up @@ -48,7 +48,7 @@
FROM
hlstats_Games
WHERE
hlstats_Games.code = '$game'
hlstats_Games.code = '" . valid_request($game, false) . "'
");
if ($db->num_rows() < 1) error("No such game '$game'.");
list($gamename) = $db->fetch_row();
Expand All @@ -66,7 +66,7 @@
FROM
hlstats_Roles
WHERE
hlstats_Roles.game='$game'
hlstats_Roles.game='" . valid_request($game, false) . "'
");
while ($rowdata = $db->fetch_row($result))
{
Expand Down Expand Up @@ -163,7 +163,7 @@
FROM
hlstats_Roles
WHERE
hlstats_Roles.game = '$game'
hlstats_Roles.game = '" . valid_request($game, false) . "'
AND hlstats_Roles.hidden = '0'
");
list($realkills, $realdeaths, $realpicked) = $db->fetch_row();
Expand All @@ -182,7 +182,7 @@
FROM
hlstats_Roles
WHERE
hlstats_Roles.game = '$game'
hlstats_Roles.game = '" . valid_request($game, false) . "'
AND hlstats_Roles.kills > 0
AND hlstats_Roles.hidden = '0'
GROUP BY
Expand Down

0 comments on commit 1d1acb3

Please sign in to comment.