-
Notifications
You must be signed in to change notification settings - Fork 2
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
ProgrammingError only '%s', '%b', '%t' are allowed as placeholders, got '%C' #15
Comments
I'm not sure what the issue is in django-pgactivity. Can you elaborate? |
As I understand, it adds context via middleware and then in the In my case URL is next Sorry if I miss something or explained in unclear way. |
I see, this makes sense! Yes this was an oversight. We should be properly escaping It's difficult for me to commit to when it could be fixed, but I welcome PRs |
Do you think will that work if we just make a next quick bug-fix in that line https://github.com/AmbitionEng/django-pgactivity/blob/86b95fe340ad67fb3f0bfc8302264e1fe4bc7cff/pgactivity/runtime.py#L17C5-L17C70 As: Or we can decode URL via unquote before passing it like. But for me it sounds first approach is better since it is not only in URL can be passed, but also as additional context via manual code (not via middleware which does it automatically) |
Hi there,
Found an issue when some spam attacks on a website like
/%C0
, we have a next issue in SQL query:I am open to fixing that issue but unsure where to start and how to fix it. Ready to provide fix on your assistance.
The text was updated successfully, but these errors were encountered: