https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=42585

--- Comment #21 from Kyle M Hall (khall) <[email protected]> ---
(In reply to Andrew Fuerste-Henry from comment #12)

Thanks Andrew! All three should be fixed!

The no findings on your query was two bugs. correlated_subquery pulled the
subquery body out with a regex that stopped at the first closing paren, s the
COUNT(*) hid it. It counts bracket depth now. And scale dependent findings were
*dropped* on a small database instead of shown. They come back suppressed now,
with the row estimate, under a "Not a problem on this database" toggle, and
don't count toward the severity. Regular expressions be hard!

The size limit was looking at how big the tables are, not how much of them the
query reads. It uses the EXPLAIN row estimate now, capped by a trailing LIMIT
when the plan can stream rows straight out. So "SELECT * FROM items LIMIT 10"
is quiet, but "ORDER BY RAND() LIMIT 1" still warns, because the sort reads
every row before the LIMIT applies.

On the password column, is_sql_valid catches one named in the SQL text and I
had that covered. A wildcard ( SELECT * FROM borrowers ) isn't caught until
execute_query looks at the result column names. forbidden_column expands
wildcards against the schema now, so your query reports borrowers.password,
borrowers.secret and borrowers.overdrive_auth_token.

Please give it another shot and let me know how it goes!

-- 
You are receiving this mail because:
You are watching all bug changes.
_______________________________________________
Koha-bugs mailing list -- [email protected]
To unsubscribe send an email to [email protected]
website : http://www.koha-community.org/
git : http://git.koha-community.org/
bugs : http://bugs.koha-community.org/

Reply via email to