aboutsummaryrefslogtreecommitdiffstats
path: root/activerecord/lib
diff options
context:
space:
mode:
authorMarcel Molina <marcel@vernix.org>2006-01-04 03:43:28 +0000
committerMarcel Molina <marcel@vernix.org>2006-01-04 03:43:28 +0000
commitbbec3ae512290eaee7942d3c073285f69c7ecf0a (patch)
tree5ee05f9cfdea0e23bad368f5546bfd03af222d55 /activerecord/lib
parent10cf9ecafc4b1953cf8289e530cab7a0a751b9c4 (diff)
downloadrails-bbec3ae512290eaee7942d3c073285f69c7ecf0a.tar.gz
rails-bbec3ae512290eaee7942d3c073285f69c7ecf0a.tar.bz2
rails-bbec3ae512290eaee7942d3c073285f69c7ecf0a.zip
Sanitize scoped conditions.
git-svn-id: http://svn-commit.rubyonrails.org/rails/trunk@3379 5ecf4fe2-1ee6-0310-87b1-e25e094e27de
Diffstat (limited to 'activerecord/lib')
-rwxr-xr-xactiverecord/lib/active_record/base.rb2
1 files changed, 1 insertions, 1 deletions
diff --git a/activerecord/lib/active_record/base.rb b/activerecord/lib/active_record/base.rb
index a08cd0f2df..94bdce5b19 100755
--- a/activerecord/lib/active_record/base.rb
+++ b/activerecord/lib/active_record/base.rb
@@ -944,7 +944,7 @@ module ActiveRecord #:nodoc:
# Adds a sanitized version of +conditions+ to the +sql+ string. Note that the passed-in +sql+ string is changed.
def add_conditions!(sql, conditions)
- segments = [scope(:find, :conditions)]
+ segments = [sanitize_sql(scope(:find, :conditions))]
segments << sanitize_sql(conditions) unless conditions.nil?
segments << type_condition unless descends_from_active_record?
segments.compact!