Revision history for SQL::Abstract
+ - Fix parsing of NOT EXISTS
+
revision 1.72 2010-12-21
----------------------------
- Extra checks of search arguments for possible SQL injection attacks
'ON',
'WHERE',
'(?: DEFAULT \s+ )? VALUES',
- 'EXISTS',
+ '(?:NOT \s+)? EXISTS',
'GROUP \s+ BY',
'HAVING',
'ORDER \s+ BY',
elsif ( $token =~ /^ NOT $/ix ) {
my $op = uc $token;
my $right = $self->_recurse_parse ($tokens, PARSE_RHS);
- $left = $left ? [ @$left, [$op => [$right] ]]
- : [ $op => [$right] ];
+ $left = $left ? [ @$left, [$op => [$right||()] ]]
+ : [ $op => [$right||()] ];
}
elsif ( $token =~ $placeholder_re) {
"SELECT * FROM (SELECT * FROM foobar) WHERE foo.a = 1 and foo.b LIKE 'station'",
"SELECT * FROM lolz WHERE ( foo.a =1 ) and foo.b LIKE 'station'",
"SELECT [screen].[id], [screen].[name], [screen].[section_id], [screen].[xtype] FROM [users_roles] [me] JOIN [roles] [role] ON [role].[id] = [me].[role_id] JOIN [roles_permissions] [role_permissions] ON [role_permissions].[role_id] = [role].[id] JOIN [permissions] [permission] ON [permission].[id] = [role_permissions].[permission_id] JOIN [permissionscreens] [permission_screens] ON [permission_screens].[permission_id] = [permission].[id] JOIN [screens] [screen] ON [screen].[id] = [permission_screens].[screen_id] WHERE ( [me].[user_id] = ? ) GROUP BY [screen].[id], [screen].[name], [screen].[section_id], [screen].[xtype]",
+ "SELECT * FROM foo WHERE NOT EXISTS (SELECT bar FROM baz)",
);
for (@sql) {