From 7ba14e20b58b5ec1837c8d5fea967d1350903e50 Mon Sep 17 00:00:00 2001 From: XANTRONIX Development Date: Tue, 26 Nov 2024 14:03:26 -0500 Subject: [PATCH] Explicitly query table column names --- lib/nntp/tiny/db.py | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/lib/nntp/tiny/db.py b/lib/nntp/tiny/db.py index c372d19..044f0af 100644 --- a/lib/nntp/tiny/db.py +++ b/lib/nntp/tiny/db.py @@ -96,7 +96,10 @@ class Database(): return cr def query(self, table, values=dict(), order_by=list()): - sql = f"select * from {table.name}" + sql = "select %s from %s" % ( + ', '.join(table.columns), + table.name + ) if len(values) > 0: sql += " where "