mirror of
https://github.com/we-promise/sure.git
synced 2026-04-19 12:04:08 +00:00
Sanitize input for ilike in Account::Entry.search (#988)
This commit is contained in:
@@ -137,7 +137,7 @@ class Account::Entry < ApplicationRecord
|
||||
|
||||
def search(params)
|
||||
query = all
|
||||
query = query.where("account_entries.name ILIKE ?", "%#{params[:search]}%") if params[:search].present?
|
||||
query = query.where("account_entries.name ILIKE ?", "%#{sanitize_sql_like(params[:search])}%") if params[:search].present?
|
||||
query = query.where("account_entries.date >= ?", params[:start_date]) if params[:start_date].present?
|
||||
query = query.where("account_entries.date <= ?", params[:end_date]) if params[:end_date].present?
|
||||
|
||||
|
||||
Reference in New Issue
Block a user