Updates
This commit is contained in:
@@ -20,6 +20,7 @@ const addDbEntry = require("./addDbEntry");
|
||||
const updateDbEntry = require("./updateDbEntry");
|
||||
const deleteDbEntry = require("./deleteDbEntry");
|
||||
const parseDbResults = require("../parseDbResults");
|
||||
const trimSql = require("../../../utils/trim-sql");
|
||||
|
||||
/** ****************************************************************************** */
|
||||
/** ****************************************************************************** */
|
||||
@@ -89,10 +90,7 @@ async function runQuery({
|
||||
*/
|
||||
try {
|
||||
if (typeof query === "string") {
|
||||
const formattedQuery = query
|
||||
.replace(/\n|\r|\n\r|\r\n/gm, " ")
|
||||
.replace(/ {2,}/g, " ")
|
||||
.trim();
|
||||
const formattedQuery = trimSql(query);
|
||||
|
||||
/**
|
||||
* Input Validation
|
||||
@@ -101,10 +99,9 @@ async function runQuery({
|
||||
*/
|
||||
if (
|
||||
readOnly &&
|
||||
(formattedQuery.match(
|
||||
formattedQuery.match(
|
||||
/^alter|^delete|information_schema|databases|^create/i
|
||||
) ||
|
||||
!formattedQuery.match(/^select|^\( ?select/i))
|
||||
)
|
||||
) {
|
||||
throw new Error("Wrong Input!");
|
||||
}
|
||||
|
||||
Vendored
+24
@@ -0,0 +1,24 @@
|
||||
export = trimSql;
|
||||
/**
|
||||
* @typedef {object} GrabHostNamesReturn
|
||||
* @property {string} host
|
||||
* @property {number | string} port
|
||||
* @property {typeof http | typeof https} scheme
|
||||
*/
|
||||
/**
|
||||
* # Trim SQL
|
||||
* @description Remove Returns and miltiple spaces from SQL Query
|
||||
* @param {string} sql
|
||||
* @returns {string}
|
||||
*/
|
||||
declare function trimSql(sql: string): string;
|
||||
declare namespace trimSql {
|
||||
export { GrabHostNamesReturn };
|
||||
}
|
||||
type GrabHostNamesReturn = {
|
||||
host: string;
|
||||
port: number | string;
|
||||
scheme: typeof http | typeof https;
|
||||
};
|
||||
import http = require("http");
|
||||
import https = require("https");
|
||||
@@ -0,0 +1,26 @@
|
||||
// @ts-check
|
||||
|
||||
const https = require("https");
|
||||
const http = require("http");
|
||||
|
||||
/**
|
||||
* @typedef {object} GrabHostNamesReturn
|
||||
* @property {string} host
|
||||
* @property {number | string} port
|
||||
* @property {typeof http | typeof https} scheme
|
||||
*/
|
||||
|
||||
/**
|
||||
* # Trim SQL
|
||||
* @description Remove Returns and miltiple spaces from SQL Query
|
||||
* @param {string} sql
|
||||
* @returns {string}
|
||||
*/
|
||||
function trimSql(sql) {
|
||||
return sql
|
||||
.replace(/\n|\r|\n\r|\r\n/gm, " ")
|
||||
.replace(/ {2,}/g, " ")
|
||||
.trim();
|
||||
}
|
||||
|
||||
module.exports = trimSql;
|
||||
Reference in New Issue
Block a user