X-Git-Url: http://git.freeside.biz/gitweb/?a=blobdiff_plain;f=httemplate%2Fsearch%2Fsql.html;h=71aa0067148e5552f8f63b838c92de8f3ba79630;hb=346c32b847002357ecf79503d153186d0627aaa1;hp=5f64ebc2860a12085b848199894442f4dd911be5;hpb=9509e5bfb7f9331303153cac24d7bfecbe2ea9f1;p=freeside.git diff --git a/httemplate/search/sql.html b/httemplate/search/sql.html index 5f64ebc28..71aa00671 100644 --- a/httemplate/search/sql.html +++ b/httemplate/search/sql.html @@ -1,13 +1,15 @@ -<% include( 'elements/search.html', +<& elements/search.html, 'title' => 'Query Results', 'name' => 'rows', - 'query' => 'SELECT '. ( $cgi->param('sql') - || eidiot('Empty query') ), - ) -%> + 'query' => "SELECT $sql", + +&> <%init> die "access denied" unless $FS::CurrentUser::CurrentUser->access_right('Raw SQL'); +my $sql = $cgi->param('sql') or errorpage('Empty query'); +$sql =~ s/;+\s*$//; #remove trailing ; +