diff --git a/app/app.go b/app/app.go index f167eeb..acf4e44 100644 --- a/app/app.go +++ b/app/app.go @@ -170,7 +170,7 @@ func (a *App) UpdateRows(c config.SchemaConfigAction, globalColumns map[string]s updates = append(updates, database.GetNamedParameter(a.DbConfig.Type, col, len(values)+1)) values[len(values)+1] = value.FinalValue() } else { - updates = append(updates, fmt.Sprintf("%s=%s", col, value.FinalValue())) + updates = append(updates, fmt.Sprintf("%s=%s", database.EscapeColumn(a.DbConfig.Type, col), value.FinalValue())) } } } @@ -179,7 +179,7 @@ func (a *App) UpdateRows(c config.SchemaConfigAction, globalColumns map[string]s value := row[col] if !value.IsString || value.IsNull { - pkeys = append(pkeys, fmt.Sprintf("%s=%s", col, value.FinalValue())) + pkeys = append(pkeys, fmt.Sprintf("%s=%s", database.EscapeColumn(a.DbConfig.Type, col), value.FinalValue())) } else { pkeys = append(pkeys, database.GetNamedParameter(a.DbConfig.Type, col, len(values)+1)) values[len(values)+1] = value.FinalValue() diff --git a/database/database.go b/database/database.go index 6a1c699..94b052b 100644 --- a/database/database.go +++ b/database/database.go @@ -15,12 +15,16 @@ func EscapeTable(dbType, table string) string { return fmt.Sprintf("\"%s\"", table) } +func EscapeColumn(dbType, col string) string { + return EscapeTable(dbType, col) +} + func GetNamedParameter(dbType, col string, number int) string { if dbType == "mysql" { - return fmt.Sprintf("%s=?", col) + return fmt.Sprintf("%s=?", EscapeColumn(col)) } - return fmt.Sprintf("%s=$%d", col, number) + return fmt.Sprintf("%s=$%d", EscapeColumn(col), number) } func IsPgNumberType(value string) bool { @@ -80,7 +84,7 @@ func GetRows(db *sql.DB, query, table, dbType string) map[int]map[string]data.Da if value != nil { if dbType == "postgres" { if len(columnsTypes[col]) == 0 { - typeQuery := fmt.Sprintf("SELECT pg_typeof(%s) as value FROM %s", col, EscapeTable(dbType, table)) + typeQuery := fmt.Sprintf("SELECT pg_typeof(%s) as value FROM %s", EscapeColumn(dbType, col), EscapeTable(dbType, table)) db.QueryRow(typeQuery).Scan(&typeValue) columnsTypes[col] = typeValue } diff --git a/database/database_test.go b/database/database_test.go index 75cc8e8..343d675 100644 --- a/database/database_test.go +++ b/database/database_test.go @@ -14,6 +14,16 @@ func TestEscapeTable(t *testing.T) { } } +func TestEscapeColumn(t *testing.T) { + if EscapeColumn("mysql", "foo") != "`foo`" { + t.Fatalf("TestEscapeColumn: mysql check failed") + } + + if EscapeTable("postgres", "foo") != "\"foo\"" { + t.Fatalf("TestEscapeColumn: postgres check failed") + } +} + func TestGetNamedParameter(t *testing.T) { if GetNamedParameter("mysql", "foo", 1) != "foo=?" { t.Fatalf("TestGetNamedParameter: mysql check failed")