From 26a39ac243cf529eb309597d71a4bf0dd2cd18e5 Mon Sep 17 00:00:00 2001 From: Jakub Vrana Date: Wed, 27 Jun 2018 09:20:06 +0200 Subject: [PATCH] Revert "PgSQL search operator "SQL" added" This reverts commit af7ac6f06af0d7912df9f640852adf95487aef20. --- adminer/drivers/pgsql.inc.php | 2 +- changes.txt | 1 - 2 files changed, 1 insertion(+), 2 deletions(-) diff --git a/adminer/drivers/pgsql.inc.php b/adminer/drivers/pgsql.inc.php index 88854cc4..fe1f069f 100644 --- a/adminer/drivers/pgsql.inc.php +++ b/adminer/drivers/pgsql.inc.php @@ -845,7 +845,7 @@ AND typelem = 0" $structured_types[$key] = array_keys($val); } $unsigned = array(); - $operators = array("=", "<", ">", "<=", ">=", "!=", "~", "!~", "LIKE", "LIKE %%", "ILIKE", "ILIKE %%", "IN", "IS NULL", "NOT LIKE", "NOT IN", "IS NOT NULL"); // no "SQL" to avoid SQL injection + $operators = array("=", "<", ">", "<=", ">=", "!=", "~", "!~", "LIKE", "LIKE %%", "ILIKE", "ILIKE %%", "IN", "IS NULL", "NOT LIKE", "NOT IN", "IS NOT NULL"); // no "SQL" to avoid CSRF $functions = array("char_length", "lower", "round", "to_hex", "to_timestamp", "upper"); $grouping = array("avg", "count", "count distinct", "max", "min", "sum"); $edit_functions = array( diff --git a/changes.txt b/changes.txt index e4a49547..278ae955 100644 --- a/changes.txt +++ b/changes.txt @@ -10,7 +10,6 @@ PDO: Support binary fields download MySQL: Disallow LOAD DATA LOCAL INFILE MySQL: Use CONVERT() only when searching for non-ASCII (bug #603) MySQL: Order database names in MySQL 8 (bug #613) -PostgreSQL: Add SQL operator to search PostgreSQL: Fix editing data in views (bug #605, regression from 4.6.0) PostgreSQL: Do not cast date/time/number/uuid searches to text (bug #608) PostgreSQL: Export false as 0 in PDO (bug #619)