Skip to content

Possible bug when using a UUID in a custom where clause #1153

Description

@jwoertink

We have this line of code:

where("approval.user_id = '?'", current_user.id)

Notice that there's single quotes around the ?. If we remove those single quotes, the query stops returning results. It doesn't fail... it just doesn't return what we need.

I think it's somewhere in this bit of code causing it, but it'll need more research to confirm

avram/src/avram/where.cr

Lines 447 to 468 in a620fae

private def build_clause(statement, bind_vars)
bind_vars.each do |arg|
encoded_arg = prepare_for_execution(arg)
statement = statement.sub('?', encoded_arg)
end
statement
end
private def prepare_for_execution(value)
if value.is_a?(Array)
"'#{PQ::Param.encode_array(value)}'"
else
escape_if_needed(value)
end
end
private def escape_if_needed(value)
if value.is_a?(String) || value.is_a?(Slice(UInt8))
PG::EscapeHelper.escape_literal(value)
else
value
end

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions