[IMP] base: correctly escape identifiers in reflection queries

When the db reflects the python models at startup, a query is generated
to update various `ir` models (models, fields, etc.). This query did not
properly escape identifiers, preventing the use of the 'order' field
name on ir.model because it is a reserved keyword in SQL and wasn't
escaped.

This commit introduces proper escaping for these reflection queries.

Co-Authored-By: Raphaël Collet <rco@odoo.com>
This commit is contained in:
Damien Bouvy
2020-01-31 12:06:46 +00:00
co-authored by Raphaël Collet
parent d25fac7e8d
commit eaccecd6cc
+5 -5
View File
@@ -47,8 +47,8 @@ def query_insert(cr, table, rows):
rows = [rows]
cols = list(rows[0])
query = INSERT_QUERY.format(
table=table,
cols=",".join(cols),
table='"{}"'.format(table),
cols=",".join(['"{}"'.format(col) for col in cols]),
rows=",".join("%s" for row in rows),
)
params = [tuple(row[col] for col in cols) for row in rows]
@@ -61,9 +61,9 @@ def query_update(cr, table, values, selectors):
"""
setters = set(values) - set(selectors)
query = UPDATE_QUERY.format(
table=table,
assignment=",".join("{0}=%({0})s".format(s) for s in setters),
condition=" AND ".join("{0}=%({0})s".format(s) for s in selectors),
table='"{}"'.format(table),
assignment=",".join('"{0}"=%({0})s'.format(s) for s in setters),
condition=" AND ".join('"{0}"=%({0})s'.format(s) for s in selectors),
)
cr.execute(query, values)
return [row[0] for row in cr.fetchall()]