Openbravo Issue Tracking System - Retail Modules
View Issue Details
0038133Retail ModulesWeb POSpublic2018-03-14 11:562018-03-19 09:36
shuehner 
Sandrahuguet 
normalminorhave not tried
closedfixed 
5
 
RR18Q2 
marvintm
No
0038133: AddPack.java has query which is not using bind-parameters
That query is not using bind-parameters but embedding data values directly into SQL text:

    final OBQuery<OrderLine> qSamePackLines = OBDal
        .getInstance()
        .createQuery(
            OrderLine.class,
            " as e where e.salesOrder='"
                + order.getId()
                + "' and exists(select 1 from OrderLineOffer offer where e = offer.salesOrderLine and offer.priceAdjustment.id = '"
                + pack.getId() + "')");

-
Use bind-parameters as usual.
No tags attached.
blocks design defect 0038136 acknowledged Triage Platform Base Openbravo ERP Tracking issue: Find & Fix queries not using bind-params but embedding values into query string 
Issue History
2018-03-14 11:56shuehnerNew Issue
2018-03-14 11:56shuehnerAssigned To => Retail
2018-03-14 11:56shuehnerTriggers an Emergency Pack => No
2018-03-14 13:03shuehnerRelationship addedblocks 0038136
2018-03-14 16:35shuehnerAssigned ToRetail => Sandrahuguet
2018-03-14 17:25SandrahuguetStatusnew => scheduled
2018-03-16 08:19hgbotCheckin
2018-03-16 08:19hgbotNote Added: 0103295
2018-03-16 08:19hgbotStatusscheduled => resolved
2018-03-16 08:19hgbotResolutionopen => fixed
2018-03-16 08:19hgbotFixed in SCM revision => http://code.openbravo.com/erp/pmods/org.openbravo.retail.discounts/rev/59ad14d4c841788b7bbe681e3750fcbbfe04b63d [^]
2018-03-16 08:28SandrahuguetReview Assigned To => marvintm
2018-03-19 09:36marvintmStatusresolved => closed
2018-03-19 09:36marvintmFixed in Version => RR18Q2

Notes
(0103295)
hgbot   
2018-03-16 08:19   
Repository: erp/pmods/org.openbravo.retail.discounts
Changeset: 59ad14d4c841788b7bbe681e3750fcbbfe04b63d
Author: Sandra Huguet <sandra.huguet <at> openbravo.com>
Date: Wed Mar 14 17:10:34 2018 +0100
URL: http://code.openbravo.com/erp/pmods/org.openbravo.retail.discounts/rev/59ad14d4c841788b7bbe681e3750fcbbfe04b63d [^]

fixed issue 38133 use bind-parameters in addPack query

---
M src/org/openbravo/retail/discounts/AddPack.java
---