forked from claw/flaskpaste
fix: use nosec for bandit SQL injection suppression
This commit is contained in:
@@ -143,7 +143,7 @@ def query_audit_log(
|
||||
|
||||
# Get total count
|
||||
count_row = db.execute(
|
||||
f"SELECT COUNT(*) as total FROM audit_log WHERE {where_sql}", # noqa: S608
|
||||
f"SELECT COUNT(*) as total FROM audit_log WHERE {where_sql}", # nosec B608
|
||||
params,
|
||||
).fetchone()
|
||||
total = count_row["total"] if count_row else 0
|
||||
@@ -155,7 +155,7 @@ def query_audit_log(
|
||||
FROM audit_log
|
||||
WHERE {where_sql}
|
||||
ORDER BY timestamp DESC
|
||||
LIMIT ? OFFSET ?""", # noqa: S608
|
||||
LIMIT ? OFFSET ?""", # nosec B608
|
||||
[*params, limit, offset],
|
||||
).fetchall()
|
||||
|
||||
|
||||
Reference in New Issue
Block a user