From f63d6cfcedca0f8b5cb82e3956ddbca7240739cb Mon Sep 17 00:00:00 2001 From: Luck Date: Fri, 30 Mar 2018 21:50:03 +0100 Subject: [PATCH] Properly escape sql query for loadTrack (#877) --- .../java/me/lucko/luckperms/common/storage/dao/sql/SqlDao.java | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/common/src/main/java/me/lucko/luckperms/common/storage/dao/sql/SqlDao.java b/common/src/main/java/me/lucko/luckperms/common/storage/dao/sql/SqlDao.java index 428d7b82..fb293baa 100644 --- a/common/src/main/java/me/lucko/luckperms/common/storage/dao/sql/SqlDao.java +++ b/common/src/main/java/me/lucko/luckperms/common/storage/dao/sql/SqlDao.java @@ -106,7 +106,7 @@ public class SqlDao extends AbstractDao { private static final String GROUP_DELETE = "DELETE FROM {prefix}groups WHERE name=?"; private static final String TRACK_INSERT = "INSERT INTO {prefix}tracks VALUES(?, ?)"; - private static final String TRACK_SELECT = "SELECT groups FROM {prefix}tracks WHERE name=?"; + private static final String TRACK_SELECT = "SELECT 'groups' FROM {prefix}tracks WHERE name=?"; private static final String TRACK_SELECT_ALL = "SELECT * FROM {prefix}tracks"; private static final String TRACK_UPDATE = "UPDATE {prefix}tracks SET groups=? WHERE name=?"; private static final String TRACK_DELETE = "DELETE FROM {prefix}tracks WHERE name=?";