Lighthouse has a new layout. Prefer the old one? Return to the old layout, and switch back any time from the link at the top of each page.

This project is archived and is in readonly mode.

validates_uniqueness_of does not escape column names

#580

validates_uniqueness_of does not escape column names before querying the database.

I've attached a patch that fixes the problem, and includes a test to reproduce the problem.

Reported by Aaron Patterson · July 9th, 2008 @ 04:45 AM

State: resolved
Milestone: 2.x
Assigned to: Pratik Pratik
Importance: none

Activity

  1. Pratik
    Pratik
    • Assigned user set to Pratik

    I'm getting many tests failures after applying the patch.

    July 14th, 2008 @ 01:39 AM

  2. Pratik
    Pratik
    • State changed from new to incomplete

    July 14th, 2008 @ 01:28 PM

  3. Alex MacCaw
  4. Aaron Patterson
    Aaron Patterson

    @Alex, no. That is escaping table names. Column names need to be escaped too.

    July 14th, 2008 @ 03:22 PM

  5. Alex MacCaw
    Alex MacCaw

    I'm pretty sure my patch was quoting column names too :)

    The difference between my patch and yours, is that you're quoting the column names in the sql conditions. Perhaps you could update this ticket to make that clear?

    July 14th, 2008 @ 03:32 PM

  6. Murray Steele
    Murray Steele

    I've a patch for this in my github fork:

    http://github.com/h-lame/rails/c...

    It's not as nice as Aaron's patch in that it doesn't have a test, but I'm pretty sure that test_validate_uniqueness_with_columns_which_are_sql_keywords (added by Alex's patch in [#23]) in validations_test already covers this (it's a break in that test that turned me on to this). Also, my patch applies the fix to activemodel too, which might be nice.

    July 22nd, 2008 @ 12:33 PM

  7. Ryan Alyea
    Ryan Alyea

    Why hasn't this been patched yet? This causes problems with MySQL 4.x. I have to manually patch for each Rails update.

    October 25th, 2008 @ 11:20 PM

  8. Murray Steele
    Murray Steele

    Actually, it looks like the bug described here has been fixed, just not with anything from this ticket.

    This is the commit that does it: http://github.com/rails/rails/co...

    This ticket could probably be closed as fixed or duplicate if there's a ticket attached to the above commit (I couldn't find one if there is though.)

    October 26th, 2008 @ 12:23 PM

  9. Frederick Cheung
    Frederick Cheung
    • State changed from incomplete to resolved

    Good call Murray!

    December 20th, 2008 @ 03:52 PM