Browse Source

troca string interpolation por prepared statements com ?

master
Henrique-Sousa 4 weeks ago
parent
commit
66a45a930d
3 changed files with 11 additions and 4 deletions
  1. BIN
      dbs/clinica.mv.db
  2. +5
    -2
      server/services/medicos/get.js
  3. +6
    -2
      server/services/pacientes/get.js

BIN
dbs/clinica.mv.db View File


+ 5
- 2
server/services/medicos/get.js View File

@ -4,8 +4,11 @@ const crm = _req.getString("crm") ?? "";
const dbRegistros = _db.query(`
SELECT nome, c_r_m
FROM medico
WHERE nome LIKE '%${nome}%' AND c_r_m LIKE '%${crm}%'
`);
WHERE nome LIKE ? AND c_r_m LIKE ?
`,
`%${nome}%`,
`%${crm}%`
);
const lista = _val.list();


+ 6
- 2
server/services/pacientes/get.js View File

@ -5,8 +5,12 @@ const cpf = _req.getString("cpf") ?? "";
const dbRegistros = _db.query(`
SELECT nome, r_g, c_p_f, data_de_nascimento, endereco, telefone
FROM paciente
WHERE nome LIKE '%${nome}%' AND r_g LIKE '%${rg}%' AND c_p_f LIKE '%${cpf}%'
`);
WHERE nome LIKE ? AND r_g LIKE ? AND c_p_f LIKE ?
`,
`%${nome}%`,
`%${rg}%`,
`%${cpf}%`
);
const lista = _val.list();


Loading…
Cancel
Save