@@ -34,7 +34,7 @@ func AllBooks() ([]Book, error) {
34
34
// The user input is not parameterized. Instead of using fmt.Sprintf() to build
35
35
// the query, you should be using a parameterized query.
36
36
func NameQuery (r string ) ([]Book , error ) {
37
- // Fix: rows, err := db .Query("SELECT * FROM books WHERE name = ?", r)
37
+ // Fix: rows, err := DB .Query("SELECT * FROM books WHERE name = ?", r)
38
38
rows , err := DB .Query (fmt .Sprintf ("SELECT * FROM books WHERE name = '%s'" , r ))
39
39
if err != nil {
40
40
return nil , err
@@ -53,7 +53,7 @@ func NameQuery(r string) ([]Book, error) {
53
53
// The user input is not parameterized. Instead of using fmt.Sprintf() to build
54
54
// the query, you should be using a parameterized query.
55
55
func AuthorQuery (r string ) ([]Book , error ) {
56
- // Fix: rows, err := db .Query("SELECT * FROM books WHERE author = ?", r)
56
+ // Fix: rows, err := DB .Query("SELECT * FROM books WHERE author = ?", r)
57
57
rows , err := DB .Query (fmt .Sprintf ("SELECT * FROM books WHERE author = '%s'" , r ))
58
58
if err != nil {
59
59
return nil , err
@@ -72,7 +72,7 @@ func AuthorQuery(r string) ([]Book, error) {
72
72
// The user input is not parameterized. Instead of using fmt.Sprintf() to build
73
73
// the query, you should be using a parameterized query.
74
74
func ReadQuery (r string ) ([]Book , error ) {
75
- // Fix: rows, err := db .Query("SELECT * FROM books WHERE read = ?", r)
75
+ // Fix: rows, err := DB .Query("SELECT * FROM books WHERE read = ?", r)
76
76
rows , err := DB .Query (fmt .Sprintf ("SELECT * FROM books WHERE read = '%s'" , r ))
77
77
if err != nil {
78
78
return nil , err
0 commit comments