Inject SQL into strings with "CREATE VIEW" (PY-17414)

This commit is contained in:
Andrey Vlasovskikh
2015-12-23 19:26:38 +03:00
parent 8db8aa0cf2
commit 18e0685313

View File

@@ -9,6 +9,6 @@
</injection>
<injection language="SQL" injector-id="python">
<display-name>"SQL select/delete/insert/update/create"</display-name>
<place><![CDATA[pyStringLiteralMatches("((SELECT|DELETE)\\s.*FROM)|((INSERT|REPLACE)\\s.*INTO)|(UPDATE\\s.*SET)|((CREATE|DROP|ALTER)\\s.*(TABLE|INDEX))")]]></place>
<place><![CDATA[pyStringLiteralMatches("((SELECT|DELETE)\\s.*FROM)|((INSERT|REPLACE)\\s.*INTO)|(UPDATE\\s.*SET)|((CREATE|DROP|ALTER)\\s.*(TABLE|INDEX|VIEW))")]]></place>
</injection>
</component>