#1368 fixed escapings

This commit is contained in:
Kartones
2014-12-05 17:30:47 +01:00
parent 626b883cfc
commit dbb6f42b99
4 changed files with 12 additions and 7 deletions
+2 -1
View File
@@ -1,7 +1,7 @@
# cartodb/Makefile # cartodb/Makefile
EXTENSION = cartodb EXTENSION = cartodb
EXTVERSION = 0.5.0 EXTVERSION = 0.5.1
SED = sed SED = sed
@@ -29,6 +29,7 @@ UPGRADABLE = \
0.3.6 \ 0.3.6 \
0.4.0 \ 0.4.0 \
0.4.1 \ 0.4.1 \
0.5.0 \
$(EXTVERSION)dev \ $(EXTVERSION)dev \
$(EXTVERSION)next \ $(EXTVERSION)next \
$(END) $(END)
+5 -1
View File
@@ -1,4 +1,8 @@
0.5.0 (2014-09-21) 0.5.1 (2014-11-21)
------------------
* Bugfix: Quota check and some organization permissions functions were not properly escaping table name.
0.5.0 (2014-11-03)
------------------ ------------------
* Support of raster tables for cartodbfication * Support of raster tables for cartodbfication
* Modified quota functions: vector tables stay the same, raster tables count as full size (as have no * Modified quota functions: vector tables stay the same, raster tables count as full size (as have no
+3 -3
View File
@@ -35,7 +35,7 @@ FUNCTION cartodb.CDB_Organization_Add_Table_Read_Permission(from_schema text, ta
AS $$ AS $$
BEGIN BEGIN
EXECUTE 'GRANT USAGE ON SCHEMA "' || from_schema || '" TO "' || to_role_name || '"'; EXECUTE 'GRANT USAGE ON SCHEMA "' || from_schema || '" TO "' || to_role_name || '"';
EXECUTE 'GRANT SELECT ON "' || from_schema || '".' || table_name || ' TO "' || to_role_name || '"'; EXECUTE 'GRANT SELECT ON "' || from_schema || '"."' || table_name || '" TO "' || to_role_name || '"';
END END
$$ LANGUAGE PLPGSQL VOLATILE; $$ LANGUAGE PLPGSQL VOLATILE;
@@ -54,7 +54,7 @@ FUNCTION cartodb.CDB_Organization_Add_Table_Read_Write_Permission(from_schema te
AS $$ AS $$
BEGIN BEGIN
EXECUTE 'GRANT USAGE ON SCHEMA "' || from_schema || '" TO "' || to_role_name || '"'; EXECUTE 'GRANT USAGE ON SCHEMA "' || from_schema || '" TO "' || to_role_name || '"';
EXECUTE 'GRANT SELECT, INSERT, UPDATE, DELETE ON "' || from_schema || '".' || table_name || ' TO "' || to_role_name || '"'; EXECUTE 'GRANT SELECT, INSERT, UPDATE, DELETE ON "' || from_schema || '"."' || table_name || '" TO "' || to_role_name || '"';
END END
$$ LANGUAGE PLPGSQL VOLATILE; $$ LANGUAGE PLPGSQL VOLATILE;
@@ -73,7 +73,7 @@ FUNCTION cartodb.CDB_Organization_Remove_Access_Permission(from_schema text, tab
RETURNS void RETURNS void
AS $$ AS $$
BEGIN BEGIN
EXECUTE 'REVOKE ALL PRIVILEGES ON TABLE "' || from_schema || '".' || table_name || ' FROM "' || to_role_name || '"'; EXECUTE 'REVOKE ALL PRIVILEGES ON TABLE "' || from_schema || '"."' || table_name || '" FROM "' || to_role_name || '"';
-- EXECUTE 'REVOKE USAGE ON SCHEMA ' || from_schema || ' FROM "' || to_role_name || '"'; -- EXECUTE 'REVOKE USAGE ON SCHEMA ' || from_schema || ' FROM "' || to_role_name || '"';
-- We need to revoke usage on schema only if we are revoking privileges from the last table where to_role_name has -- We need to revoke usage on schema only if we are revoking privileges from the last table where to_role_name has
-- any permission granted within the schema from_schema -- any permission granted within the schema from_schema
+2 -2
View File
@@ -10,7 +10,7 @@ BEGIN
-- Also, "table_name" sounds sensible to search_path -- Also, "table_name" sounds sensible to search_path
-- Division by 2 is for not counting the_geom_webmercator -- Division by 2 is for not counting the_geom_webmercator
SELECT COALESCE(INT8(SUM(pg_total_relation_size(schema_name || '.' || table_name)) / 2), 0) INTO quota_vector SELECT COALESCE(INT8(SUM(pg_total_relation_size('"' || schema_name || '"."' || table_name || '"')) / 2), 0) INTO quota_vector
FROM information_schema.tables FROM information_schema.tables
WHERE table_catalog = current_database() AND table_schema = schema_name WHERE table_catalog = current_database() AND table_schema = schema_name
AND table_name != 'spatial_ref_sys' AND table_name != 'spatial_ref_sys'
@@ -28,7 +28,7 @@ BEGIN
AND o_table_schema = schema_name AND o_table_catalog = current_database() AND o_table_schema = schema_name AND o_table_catalog = current_database()
); );
SELECT COALESCE(INT8(SUM(pg_total_relation_size(schema_name || '.' || table_name))), 0) INTO quota_raster SELECT COALESCE(INT8(SUM(pg_total_relation_size('"' || schema_name || '"."' || table_name || '"'))), 0) INTO quota_raster
FROM information_schema.tables FROM information_schema.tables
WHERE table_catalog = current_database() AND table_schema = schema_name WHERE table_catalog = current_database() AND table_schema = schema_name
AND table_name != 'spatial_ref_sys' AND table_name != 'spatial_ref_sys'