Escape apostrophizes char on filter

This commit is contained in:
Xavier J 2016-10-19 15:10:12 +02:00
parent a781473b42
commit fd9eaa5a4d
2 changed files with 11 additions and 1 deletions

View file

@ -129,7 +129,7 @@ class DossiersListGestionnaireService
def where_filter
filter_preference_list.inject('') do |acc, preference|
unless preference.filter.blank?
filter = preference.filter.gsub('*', '%')
filter = preference.filter.gsub('*', '%').gsub("'", "''")
filter = "%"+filter+"%" unless filter.include? '%'
value = preference.table_with_s_attr