Created April 25, 2023 13:37
CodeQL Workshop Sample - DC44131, 2023
from flask import Flask, request, render_template
import psycopg2
app = Flask(__name__)
conn = psycopg2.connect("dbname=workshop user=postgres")
def lookup(data):
cursor = conn.cursor()
query = f"SELECT * FROM metadata WHERE name='{data}' OR data='{data}'"
return cursor.fetchall()
def index():
search = request.args.get("search")
results = lookup(search)
return render_template(
"search.html", results=results
if __name__ == "__main__":
