@@ -40,7 +40,7 @@ exports.isValidApiKey = function(secret, callback){
4040 pool . getConnection ( function ( err , connection ) {
4141 if ( err ) { console . log ( err ) ; callback ( true ) ; return ; }
4242
43- let sql = "SELECT valid from apikeys WHERE secret = '?' ;" ;
43+ let sql = "SELECT * from apikeys WHERE secret = ? ;" ;
4444
4545 // make the query
4646 connection . query ( sql , [ secret ] , function ( err , results ) {
@@ -74,7 +74,7 @@ exports.getUserByHash = function(hash, callback){
7474 pool . getConnection ( function ( err , connection ) {
7575 if ( err ) { console . log ( err ) ; callback ( true ) ; return ; }
7676
77- let sql = "SELECT email, firstname from entries WHERE confirm_key = '?' ;" ;
77+ let sql = "SELECT email, firstname from entries WHERE confirm_key = ? ;" ;
7878
7979 // make the query
8080 connection . query ( sql , [ hash ] , function ( err , results ) {
@@ -121,7 +121,7 @@ exports.saveEntry = function(fields, callback){
121121 if ( err ) { console . log ( err ) ; callback ( true ) ; return ; }
122122 let data = prepareEntry ( fields ) ;
123123
124- let sqlEmailExists = "SELECT count(*) as cnt FROM entries WHERE email = '?' ;" ;
124+ let sqlEmailExists = "SELECT count(*) as cnt FROM entries WHERE email = ? ;" ;
125125 connection . query ( sqlEmailExists , [ data . email ] , function ( err , results ) {
126126 if ( ! err ) {
127127 if ( results [ 0 ] [ 'cnt' ] > 0 ) {
@@ -130,7 +130,7 @@ exports.saveEntry = function(fields, callback){
130130 } else {
131131 let sql = "INSERT INTO entries (firstname, lastname, email, country, message, anon, ipv4, image, "
132132 + "created_at, updated_at, confirm_key, beta, newsletter, pax) "
133- + "VALUES ('?', '?', '?', '?', '?' , ?, '?', '?' , ?, ?, '?' , ?, ?, ?);" ;
133+ + "VALUES (?, ?, ?, ?, ? , ?, ?, ? , ?, ?, ? , ?, ?, ?);" ;
134134
135135 // run the query
136136 connection . query (
@@ -153,6 +153,7 @@ exports.saveEntry = function(fields, callback){
153153 ] ,
154154 function ( err , results ) {
155155 connection . release ( ) ;
156+ console . log ( 'this.sql' , this . sql ) ; //command/query
156157 if ( err ) { callback ( true ) ; return ; }
157158 callback ( false , results ) ;
158159 }
0 commit comments