Closed (fixed)
Project:
Services
Version:
6.x-3.x-dev
Component:
Code
Priority:
Normal
Category:
Bug report
Assigned:
Unassigned
Reporter:
Created:
3 Jan 2011 at 20:39 UTC
Updated:
26 Jan 2011 at 17:10 UTC
Jump to comment: Most recent file
Comments
Comment #1
ygerasimov commentedThis happens because of typo in _user_resource_index()
Also double escaping take place when paramaters passed.
To avoid sql injection we can escape fieldname earlier:
Please review attached patch.
If this patch is ok we will also need to look into other resources index methods.
Comment #2
kylebrowning commentedFixed and committed
Comment #3
polarbear128 commentedAha ygerasimov, we meet again!
I just picked up on this one myself in the beta2 release.
Any idea when the next beta will be released?
Comment #4
ygerasimov commented@polarbear128 nice to meet you again :)
There is some discussion about release in #987180: Don't allow GET-requests for resource actions in the REST server but I think final desicion is by heyrocker and/or kylebrowning as well as other maintainers.
You can check with them it for example on IRC channel #drupal-services.