When we call user resource index method with parameters passed it causes SQL error.

You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near 'type for db_type_placeholder LIMIT 0, 20' at line 1 query: SELECT * FROM users WHERE name = unsupported type for db_type_placeholder LIMIT 0, 20

Comments

ygerasimov’s picture

Status: Active » Needs review
StatusFileSize
new4.29 KB

This happens because of typo in _user_resource_index()

-  $schema = drupal_get_schema('node');
+  $schema = drupal_get_schema('users');

Also double escaping take place when paramaters passed.

-  $where = !empty($where) ? ' WHERE '. db_escape_string(implode(' AND ', $where)) : '';
+  $where = !empty($where) ? ' WHERE '. implode(' AND ', $where) : '';

To avoid sql injection we can escape fieldname earlier:

-    $where[] = $field . ' = ' . db_type_placeholder($schema['fields'][$field]['type']);
+    $where[] = db_escape_string($field) . ' = ' . db_type_placeholder($schema['fields'][$field]['type']);

Please review attached patch.

If this patch is ok we will also need to look into other resources index methods.

kylebrowning’s picture

Status: Needs review » Fixed

Fixed and committed

polarbear128’s picture

Aha ygerasimov, we meet again!

I just picked up on this one myself in the beta2 release.

Any idea when the next beta will be released?

ygerasimov’s picture

@polarbear128 nice to meet you again :)

There is some discussion about release in #987180: Don't allow GET-requests for resource actions in the REST server but I think final desicion is by heyrocker and/or kylebrowning as well as other maintainers.

You can check with them it for example on IRC channel #drupal-services.

Status: Fixed » Closed (fixed)

Automatically closed -- issue fixed for 2 weeks with no activity.