diff --git a/orm/services/customer_manager/cms_rest/data/sql_alchemy/cms_user_record.py b/orm/services/customer_manager/cms_rest/data/sql_alchemy/cms_user_record.py index a6494eb0..33edbe5d 100755 --- a/orm/services/customer_manager/cms_rest/data/sql_alchemy/cms_user_record.py +++ b/orm/services/customer_manager/cms_rest/data/sql_alchemy/cms_user_record.py @@ -38,7 +38,9 @@ class CmsUserRecord: raise def get_cms_user_id_from_name(self, cms_user_name): - result = self.session.connection().scalar("SELECT id from cms_user WHERE name = \"%s\"", (cms_user_name,)) + cmd = "SELECT id from cms_user WHERE name = %s" + result = self.session.connection().scalar(cmd, (cms_user_name,)) + if result is not None: return int(result) return result diff --git a/orm/services/customer_manager/cms_rest/data/sql_alchemy/user_role_record.py b/orm/services/customer_manager/cms_rest/data/sql_alchemy/user_role_record.py index aaf11112..621b224d 100755 --- a/orm/services/customer_manager/cms_rest/data/sql_alchemy/user_role_record.py +++ b/orm/services/customer_manager/cms_rest/data/sql_alchemy/user_role_record.py @@ -66,7 +66,7 @@ class UserRoleRecord: elif region_id > -1: user_check = ''' SELECT DISTINCT user_id from user_role - WHERE customer_id =%d AND region_id =%d AND user_id =%d" + WHERE customer_id =%d AND region_id =%d AND user_id =%d ''' % (customer_id, region_id, user_id) # nosec result = self.session.connection().execute(user_check)