Skip to content

Commit 47d403f

Browse files
author
patched.codes[bot]
committed
Patched sqli/dao/student.py
1 parent e3dd1d3 commit 47d403f

File tree

1 file changed

+3
-2
lines changed

1 file changed

+3
-2
lines changed

sqli/dao/student.py

Lines changed: 3 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -40,8 +40,9 @@ async def get_many(conn: Connection, limit: Optional[int] = None,
4040
@staticmethod
4141
async def create(conn: Connection, name: str):
4242
q = ("INSERT INTO students (name) "
43-
"VALUES ('%(name)s')" % {'name': name})
43+
"VALUES (%s)")
4444
async with conn.cursor() as cur:
45-
await cur.execute(q)
45+
await cur.execute(q, (name,))
46+
4647

4748

0 commit comments

Comments
 (0)