Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion src/article_del.c
Original file line number Diff line number Diff line change
Expand Up @@ -80,7 +80,7 @@ int article_del(const SECTION_LIST *p_section, const ARTICLE *p_article)
db = db_open();
if (db == NULL)
{
log_error("db_open() error: %s", mysql_error(db));
log_error("db_open() error");
ret = -1;
goto cleanup;
}
Expand Down
2 changes: 1 addition & 1 deletion src/article_op.c
Original file line number Diff line number Diff line change
Expand Up @@ -59,7 +59,7 @@ int article_excerption_set(SECTION_LIST *p_section, int32_t aid, int8_t set)
db = db_open();
if (db == NULL)
{
log_error("db_open() error: %s", mysql_error(db));
log_error("db_open() error");
ret = -1;
goto cleanup;
}
Expand Down
10 changes: 5 additions & 5 deletions src/article_post.c
Original file line number Diff line number Diff line change
Expand Up @@ -247,7 +247,7 @@ int article_post(const SECTION_LIST *p_section, ARTICLE *p_article_new)
db = db_open();
if (db == NULL)
{
log_error("db_open() error: %s", mysql_error(db));
log_error("db_open() error");
ret = -1;
goto cleanup;
}
Expand Down Expand Up @@ -470,7 +470,7 @@ int article_modify(const SECTION_LIST *p_section, const ARTICLE *p_article, ARTI
db = db_open();
if (db == NULL)
{
log_error("db_open() error: %s", mysql_error(db));
log_error("db_open() error");
ret = -1;
goto cleanup;
}
Expand Down Expand Up @@ -619,7 +619,7 @@ int article_modify(const SECTION_LIST *p_section, const ARTICLE *p_article, ARTI
db = db_open();
if (db == NULL)
{
log_error("db_open() error: %s", mysql_error(db));
log_error("db_open() error");
ret = -1;
goto cleanup;
}
Expand Down Expand Up @@ -801,7 +801,7 @@ int article_reply(const SECTION_LIST *p_section, const ARTICLE *p_article, ARTIC
db = db_open();
if (db == NULL)
{
log_error("db_open() error: %s", mysql_error(db));
log_error("db_open() error");
ret = -1;
goto cleanup;
}
Expand Down Expand Up @@ -1109,7 +1109,7 @@ int article_reply(const SECTION_LIST *p_section, const ARTICLE *p_article, ARTIC
db = db_open();
if (db == NULL)
{
log_error("db_open() error: %s", mysql_error(db));
log_error("db_open() error");
ret = -1;
goto cleanup;
}
Expand Down
14 changes: 10 additions & 4 deletions src/login.c
Original file line number Diff line number Diff line change
Expand Up @@ -115,6 +115,8 @@ int check_user(const char *username, const char *password)
int i;
int ok = 1;
char user_tz_env[BBS_user_tz_max_len + 2];
char username_f[BBS_username_max_len * 2 + 1];
char password_f[BBS_password_max_len * 2 + 1];

db = db_open();
if (db == NULL)
Expand Down Expand Up @@ -154,6 +156,10 @@ int check_user(const char *username, const char *password)
goto cleanup;
}

// Secure SQL parameters
mysql_real_escape_string(db, username_f, username, (unsigned long)strnlen(username, sizeof(username)));
mysql_real_escape_string(db, password_f, password, (unsigned long)strnlen(password, sizeof(password)));

// Begin transaction
if (mysql_query(db, "SET autocommit=0") != 0)
{
Expand Down Expand Up @@ -211,7 +217,7 @@ int check_user(const char *username, const char *password)
"WHERE user_err_login_log.username = '%s' "
"AND (user_err_login_log.login_dt >= user_pubinfo.last_login_dt "
"OR user_pubinfo.last_login_dt IS NULL)",
username);
username_f);
if (mysql_query(db, sql) != 0)
{
log_error("Query user_list error: %s", mysql_error(db));
Expand Down Expand Up @@ -239,7 +245,7 @@ int check_user(const char *username, const char *password)
snprintf(sql, sizeof(sql),
"SELECT UID, username, p_login FROM user_list "
"WHERE username = '%s' AND password = SHA2('%s', 256) AND enable",
username, password);
username_f, password_f);
if (mysql_query(db, sql) != 0)
{
log_error("Query user_list error: %s", mysql_error(db));
Expand Down Expand Up @@ -297,7 +303,7 @@ int check_user(const char *username, const char *password)
snprintf(sql, sizeof(sql),
"INSERT INTO user_err_login_log(username, password, login_dt, login_ip) "
"VALUES('%s', '%s', NOW(), '%s')",
username, password, hostaddr_client);
username_f, password_f, hostaddr_client);
if (mysql_query(db, sql) != 0)
{
log_error("Insert into user_err_login_log error: %s", mysql_error(db));
Expand Down Expand Up @@ -603,7 +609,7 @@ int user_online_update(const char *action)
db = db_open();
if (db == NULL)
{
log_error("db_open() error: %s", mysql_error(db));
log_error("db_open() error");
return -1;
}

Expand Down
2 changes: 1 addition & 1 deletion src/main.c
Original file line number Diff line number Diff line change
Expand Up @@ -523,7 +523,7 @@ int main(int argc, char *argv[])
}
if (unlink(VAR_USER_LIST_SHM) < 0)
{
log_error("unlink(%s) error", VAR_SECTION_LIST_SHM);
log_error("unlink(%s) error", VAR_USER_LIST_SHM);
}

log_common("Main process exit normally");
Expand Down
8 changes: 4 additions & 4 deletions src/section_list_loader.c
Original file line number Diff line number Diff line change
Expand Up @@ -54,7 +54,7 @@ int load_section_config_from_db(int update_gen_ex)
db = db_open();
if (db == NULL)
{
log_error("db_open() error: %s", mysql_error(db));
log_error("db_open() error");
ret = -1;
goto cleanup;
}
Expand Down Expand Up @@ -208,7 +208,7 @@ int append_articles_from_db(int32_t start_aid, int global_lock, int article_coun
db = db_open();
if (db == NULL)
{
log_error("db_open() error: %s", mysql_error(db));
log_error("db_open() error");
ret = -1;
goto cleanup;
}
Expand Down Expand Up @@ -367,7 +367,7 @@ int set_last_article_op_log_from_db(void)
db = db_open();
if (db == NULL)
{
log_error("db_open() error: %s", mysql_error(db));
log_error("db_open() error");
ret = -1;
goto cleanup;
}
Expand Down Expand Up @@ -418,7 +418,7 @@ int apply_article_op_log_from_db(int op_count_limit)
db = db_open();
if (db == NULL)
{
log_error("db_open() error: %s", mysql_error(db));
log_error("db_open() error");
ret = -1;
goto cleanup;
}
Expand Down
8 changes: 4 additions & 4 deletions src/user_info_update.c
Original file line number Diff line number Diff line change
Expand Up @@ -53,7 +53,7 @@ int user_intro_edit(int uid)
db = db_open();
if (db == NULL)
{
log_error("db_open() error: %s", mysql_error(db));
log_error("db_open() error");
ret = -1;
goto cleanup;
}
Expand Down Expand Up @@ -154,7 +154,7 @@ int user_intro_edit(int uid)
db = db_open();
if (db == NULL)
{
log_error("db_open() error: %s", mysql_error(db));
log_error("db_open() error");
ret = -1;
goto cleanup;
}
Expand Down Expand Up @@ -222,7 +222,7 @@ int user_sign_edit(int uid)
db = db_open();
if (db == NULL)
{
log_error("db_open() error: %s", mysql_error(db));
log_error("db_open() error");
ret = -1;
goto cleanup;
}
Expand Down Expand Up @@ -324,7 +324,7 @@ int user_sign_edit(int uid)
db = db_open();
if (db == NULL)
{
log_error("db_open() error: %s", mysql_error(db));
log_error("db_open() error");
ret = -1;
goto cleanup;
}
Expand Down
2 changes: 1 addition & 1 deletion src/user_list.c
Original file line number Diff line number Diff line change
Expand Up @@ -608,7 +608,7 @@ int user_list_pool_reload(int online_user)
db = db_open();
if (db == NULL)
{
log_error("db_open() error: %s", mysql_error(db));
log_error("db_open() error");
return -1;
}

Expand Down
Loading