mirror of
https://github.com/rickbarrette/redmine_qbo.git
synced 2026-04-02 08:21:57 -04:00
Sanitize search, no little bobby tables
This commit is contained in:
@@ -169,6 +169,7 @@ class Customer < ActiveRecord::Base
|
|||||||
|
|
||||||
# Searchs the database for a customer by name or phone number with out special chars
|
# Searchs the database for a customer by name or phone number with out special chars
|
||||||
def self.search(search)
|
def self.search(search)
|
||||||
|
search = sanitize_sql_like(search)
|
||||||
customers = where("name LIKE ? OR phone_number LIKE ? OR mobile_phone_number LIKE ?", "%#{search}%", "%#{search}%", "%#{search}%")
|
customers = where("name LIKE ? OR phone_number LIKE ? OR mobile_phone_number LIKE ?", "%#{search}%", "%#{search}%", "%#{search}%")
|
||||||
return customers.order(:name)
|
return customers.order(:name)
|
||||||
end
|
end
|
||||||
|
|||||||
Reference in New Issue
Block a user