stopped lisp symbols as values from being able to inject sql (SECURITY BUG)
authorRuss Tyndall <russ@acceleration.net>
Wed, 22 Jun 2011 14:43:02 +0000 (10:43 -0400)
committerNathan Bird <nathan@acceleration.net>
Thu, 30 Jun 2011 21:13:17 +0000 (17:13 -0400)
commitd86f73be9a261b9c071ab905aeff5d1ee30a3f31
treeb5effe2672a77e4c8b95f4987d32b580898f8013
parent534a26be238d2e54737488acfa96456905e57646
stopped lisp symbols as values from being able to inject sql (SECURITY BUG)

Fixed some more places where we should have been using escaped-database-identifier
sql/expressions.lisp