[FIX] Security fixes for sql injections
[odoo/odoo.git] / addons / account / project / report / analytic_balance.py
index 9e96dfd..57209f6 100644 (file)
@@ -1,21 +1,20 @@
-# -*- encoding: utf-8 -*-
+# -*- coding: utf-8 -*-
 ##############################################################################
 #
-#    OpenERP, Open Source Management Solution  
-#    Copyright (C) 2004-2009 Tiny SPRL (<http://tiny.be>). All Rights Reserved
-#    $Id$
+#    OpenERP, Open Source Management Solution
+#    Copyright (C) 2004-2010 Tiny SPRL (<http://tiny.be>).
 #
 #    This program is free software: you can redistribute it and/or modify
-#    it under the terms of the GNU General Public License as published by
-#    the Free Software Foundation, either version 3 of the License, or
-#    (at your option) any later version.
+#    it under the terms of the GNU Affero General Public License as
+#    published by the Free Software Foundation, either version 3 of the
+#    License, or (at your option) any later version.
 #
 #    This program is distributed in the hope that it will be useful,
 #    but WITHOUT ANY WARRANTY; without even the implied warranty of
 #    MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
-#    GNU General Public License for more details.
+#    GNU Affero General Public License for more details.
 #
-#    You should have received a copy of the GNU General Public License
+#    You should have received a copy of the GNU Affero General Public License
 #    along with this program.  If not, see <http://www.gnu.org/licenses/>.
 #
 ##############################################################################
@@ -33,22 +32,16 @@ class account_analytic_balance(report_sxw.rml_parse):
             'get_objects': self._get_objects,
             'lines_g': self._lines_g,
             'move_sum': self._move_sum,
-#            'move_sum_debit': self._move_sum_debit,
-#            'move_sum_credit': self._move_sum_credit,
             'sum_all': self._sum_all,
-#            'sum_debit': self._sum_debit,
-#            'sum_credit': self._sum_credit,
             'sum_balance': self._sum_balance,
-#            'sum_quantity': self._sum_quantity,
             'move_sum_balance': self._move_sum_balance,
-#            'move_sum_quantity': self._move_sum_quantity,
         })
         self.acc_ids = []
         self.read_data = []
         self.empty_acc = False
         self.acc_data_dict = {}# maintains a relation with an account with its successors.
         self.acc_sum_list = []# maintains a list of all ids
-        
+
     def get_children(self, ids):
         ids2 = []
         read_data = self.pool.get('account.analytic.account').read(self.cr, self.uid, ids,['child_ids','code','complete_name','balance'])
@@ -57,23 +50,23 @@ class account_analytic_balance(report_sxw.rml_parse):
                 inculde_empty =  True
                 if (not self.empty_acc) and data['balance'] == 0.00:
                     inculde_empty = False
-                if inculde_empty:    
+                if inculde_empty:
                     self.acc_ids.append(data['id'])
                     self.read_data.append(data)
                     if data['child_ids']:
-                        res = self.get_children(data['child_ids'])    
-        return True        
-        
-        
+                        res = self.get_children(data['child_ids'])
+        return True
+
+
     def _get_objects(self, empty_acc):
         if self.read_data:
             return self.read_data
         self.empty_acc = empty_acc
         self.read_data = []
         self.get_children(self.ids)
-        
+
         return self.read_data
-    
+
     def _lines_g(self, account_id, date1, date2):
         account_analytic_obj = self.pool.get('account.analytic.account')
         ids = account_analytic_obj.search(self.cr, self.uid,
@@ -82,12 +75,12 @@ class account_analytic_balance(report_sxw.rml_parse):
                     sum(aal.amount) AS balance, sum(aal.unit_amount) AS quantity \
                 FROM account_analytic_line AS aal, account_account AS aa \
                 WHERE (aal.general_account_id=aa.id) \
-                    AND (aal.account_id in (" + ','.join(map(str, ids)) + "))\
+                    AND (aal.account_id in aal.account_id in %s)\
                     AND (date>=%s) AND (date<=%s) AND aa.active \
                 GROUP BY aal.general_account_id, aa.name, aa.code, aal.code \
-                ORDER BY aal.code", (date1, date2))
+                ORDER BY aal.code", (tuple(ids),date1, date2))
         res = self.cr.dictfetchall()
-        
+
         for r in res:
             if r['balance'] > 0:
                 r['debit'] = r['balance']
@@ -100,7 +93,7 @@ class account_analytic_balance(report_sxw.rml_parse):
                 r['debit'] = 0.0
                 r['credit'] = 0.0
         return res
-    
+
     def _move_sum(self, account_id, date1, date2, option):
         if account_id not in self.acc_data_dict:
             account_analytic_obj = self.pool.get('account.analytic.account')
@@ -108,66 +101,28 @@ class account_analytic_balance(report_sxw.rml_parse):
             self.acc_data_dict[account_id] = ids
         else:
             ids = self.acc_data_dict[account_id]
-        
+            
+        query_params = (tuple(ids), date1, date2)
         if option == "credit" :
             self.cr.execute("SELECT -sum(amount) FROM account_analytic_line \
-                    WHERE account_id in ("+ ','.join(map(str, ids)) +") \
-                        AND date>=%s AND date<=%s AND amount<0",
-                    (date1, date2))
+                    WHERE account_id in %s AND date>=%s AND date<=%s AND amount<0",query_params)
         elif option == "debit" :
             self.cr.execute("SELECT sum(amount) FROM account_analytic_line \
-                    WHERE account_id in ("+ ','.join(map(str, ids)) +") \
-                        AND date>=%s AND date<=%s AND amount>0",
-                    (date1, date2))
+                    WHERE account_id in %s\
+                        AND date>=%s AND date<=%s AND amount>0",query_params)
         elif option == "quantity" :
             self.cr.execute("SELECT sum(unit_amount) FROM account_analytic_line \
-                WHERE account_id in ("+ ','.join(map(str, ids)) +") \
-                    AND date>=%s AND date<=%s",
-                (date1, date2))
+                WHERE account_id in %s\
+                    AND date>=%s AND date<=%s",query_params)
         return self.cr.fetchone()[0] or 0.0
-        
-
-#    def _move_sum_debit(self, account_id, date1, date2):
-#        account_analytic_obj = self.pool.get('account.analytic.account')
-#        ids = account_analytic_obj.search(self.cr, self.uid,
-#                [('parent_id', 'child_of', [account_id])])
-#        self.cr.execute("SELECT sum(amount) \
-#                FROM account_analytic_line \
-#                WHERE account_id in ("+ ','.join(map(str, ids)) +") \
-#                    AND date>=%s AND date<=%s AND amount>0",
-#                (date1, date2))
-#        return self.cr.fetchone()[0] or 0.0
-#
-#    def _move_sum_credit(self, account_id, date1, date2):
-#        account_analytic_obj = self.pool.get('account.analytic.account')
-#        ids = account_analytic_obj.search(self.cr, self.uid,
-#                [('parent_id', 'child_of', [account_id])])
-#        self.cr.execute("SELECT -sum(amount) \
-#                FROM account_analytic_line \
-#                WHERE account_id in ("+ ','.join(map(str, ids)) +") \
-#                    AND date>=%s AND date<=%s AND amount<0",
-#                (date1, date2))
-#        return self.cr.fetchone()[0] or 0.0
-#    
+
     def _move_sum_balance(self, account_id, date1, date2):
-        debit = self._move_sum(account_id, date1, date2, 'debit') 
+        debit = self._move_sum(account_id, date1, date2, 'debit')
         credit = self._move_sum(account_id, date1, date2, 'credit')
         return (debit-credit)
-    
-#    def _move_sum_quantity(self, account_id, date1, date2):
-#        account_analytic_obj = self.pool.get('account.analytic.account')
-#        ids = account_analytic_obj.search(self.cr, self.uid,
-#                [('parent_id', 'child_of', [account_id])])
-#        self.cr.execute("SELECT sum(unit_amount) \
-#                FROM account_analytic_line \
-#                WHERE account_id in ("+ ','.join(map(str, ids)) +") \
-#                    AND date>=%s AND date<=%s",
-#                (date1, date2))
-#        return self.cr.fetchone()[0] or 0.0
 
     def _sum_all(self, accounts, date1, date2, option):
         ids = map(lambda x: x['id'], accounts)
-        
         if not len(ids):
             return 0.0
 
@@ -177,72 +132,25 @@ class account_analytic_balance(report_sxw.rml_parse):
             self.acc_sum_list = ids2
         else:
             ids2 = self.acc_sum_list
-
+            query_params = (tuple(ids2), date1, date2)
         if option == "debit" :
             self.cr.execute("SELECT sum(amount) FROM account_analytic_line \
-                    WHERE account_id IN ("+','.join(map(str, ids2))+") \
-                        AND date>=%s AND date<=%s AND amount>0",
-                    (date1, date2))
+                    WHERE account_id =ANY(%s) AND date>=%s AND date<=%s AND amount>0",query_params)
         elif option == "credit" :
             self.cr.execute("SELECT -sum(amount) FROM account_analytic_line \
-                    WHERE account_id IN ("+','.join(map(str, ids2))+") \
-                        AND date>=%s AND date<=%s AND amount<0",
-                    (date1, date2))
+                    WHERE account_id =ANY(%s) AND date>=%s AND date<=%s AND amount<0",query_params)
         elif option == "quantity" :
             self.cr.execute("SELECT sum(unit_amount) FROM account_analytic_line \
-                    WHERE account_id IN ("+','.join(map(str, ids2))+") \
-                        AND date>=%s AND date<=%s",
-                    (date1, date2))
+                    WHERE account_id =ANY(%s)AND date>=%s AND date<=%s",query_params)
         return self.cr.fetchone()[0] or 0.0
 
-    
-#    def _sum_debit(self, accounts, date1, date2):
-#        ids = map(lambda x: x['id'], accounts)
-#        if not len(ids):
-#            return 0.0
-#        account_analytic_obj = self.pool.get('account.analytic.account')
-#        ids2 = account_analytic_obj.search(self.cr, self.uid,
-#                [('parent_id', 'child_of', ids)])
-#        self.cr.execute("SELECT sum(amount) \
-#                FROM account_analytic_line \
-#                WHERE account_id IN ("+','.join(map(str, ids2))+") \
-#                    AND date>=%s AND date<=%s AND amount>0",
-#                (date1, date2))
-#        return self.cr.fetchone()[0] or 0.0
-#        
-#    def _sum_credit(self, accounts, date1, date2):
-#        ids = map(lambda x: x['id'], accounts)
-#        if not len(ids):
-#            return 0.0
-#        ids = map(lambda x: x['id'], accounts)
-#        account_analytic_obj = self.pool.get('account.analytic.account')
-#        ids2 = account_analytic_obj.search(self.cr, self.uid,
-#                [('parent_id', 'child_of', ids)])
-#        self.cr.execute("SELECT -sum(amount) \
-#                FROM account_analytic_line \
-#                WHERE account_id IN ("+','.join(map(str, ids2))+") \
-#                    AND date>=%s AND date<=%s AND amount<0",
-#                (date1, date2))
-#        return self.cr.fetchone()[0] or 0.0
+
 
     def _sum_balance(self, accounts, date1, date2):
         debit = self._sum_all(accounts, date1, date2, 'debit') or 0.0
         credit = self._sum_all(accounts, date1, date2, 'credit') or 0.0
         return (debit-credit)
 
-#    def _sum_quantity(self, accounts, date1, date2):
-#        ids = map(lambda x: x['id'], accounts)
-#        if not len(ids):
-#            return 0.0
-#        account_analytic_obj = self.pool.get('account.analytic.account')
-#        ids2 = account_analytic_obj.search(self.cr, self.uid,
-#                [('parent_id', 'child_of', ids)])
-#        self.cr.execute("SELECT sum(unit_amount) \
-#                FROM account_analytic_line \
-#                WHERE account_id IN ("+','.join(map(str, ids2))+") \
-#                    AND date>=%s AND date<=%s",
-#                (date1, date2))
-#        return self.cr.fetchone()[0] or 0.0
 
 report_sxw.report_sxw('report.account.analytic.account.balance',
         'account.analytic.account', 'addons/account/project/report/analytic_balance.rml',