Lighthouse has a new layout. Prefer the old one? Return to the old layout, and switch back any time from the link at the top of each page.

This project is archived and is in readonly mode.

PostgreSQL: name in CREATE DATABASE is not properly escaped

#456

The name of the new database is not properly escaped on line 509 of the postgresql_adapter.rb. This gives problems when for example your database name contains dots. Changing the line to the following fixes the problem (single quotes do not fix the problem):

execute "CREATE DATABASE \"#{name}\"#{option_string}"

Reported by Roel van der Hoorn · June 20th, 2008 @ 09:06 AM

State: duplicate
Milestone: 2.1.1
Assigned to: nobody
Importance: none

Activity

  1. Jeremy Kemper
    Jeremy Kemper
    • Milestone set to 2.1.1
    • State changed from new to incomplete

    Please extract to quote_database_name and add a test case.

    June 20th, 2008 @ 09:43 AM

  2. Roel van der Hoorn
    Roel van der Hoorn

    I'm unable to find existing tests relating to this functionality, but the following should test it I guess.

    def test_should_create_database_with_dot
      assert_nothing_raised do
        create_database("r.vanderhoorn")
      end
    end
    

    June 20th, 2008 @ 10:13 AM

  3. Irene
    Irene
    • Tag set to 2.1, postgresql, quoting

    Same with the drop database:

    
    def drop_database(name) #:nodoc:
      execute "DROP DATABASE IF EXISTS #{name}"
    end
    

    Should be:

    
    def drop_database(name) #:nodoc:
      execute "DROP DATABASE IF EXISTS \"#{name}\""
    end
    

    August 20th, 2008 @ 06:14 PM

  4. Roel van der Hoorn
    Roel van der Hoorn

    Looks like both issues were fixed in 2.1.1.

    September 11th, 2008 @ 04:50 PM

  5. Jeremy Kemper
    Jeremy Kemper
    • State changed from incomplete to duplicate

    September 11th, 2008 @ 04:52 PM