You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
cur.execute("SELECT userId FROM users WHERE email = '"+session['email']+"'")
226
+
cur.execute("SELECT userId FROM users WHERE email = ?", (session['email'], ))
227
227
userId=cur.fetchone()[0]
228
228
try:
229
229
cur.execute("INSERT INTO kart (userId, productId) VALUES (?, ?)", (userId, productId))
@@ -243,9 +243,9 @@ def cart():
243
243
email=session['email']
244
244
withsqlite3.connect('database.db') asconn:
245
245
cur=conn.cursor()
246
-
cur.execute("SELECT userId FROM users WHERE email = '"+email+"'")
246
+
cur.execute("SELECT userId FROM users WHERE email = ?", (email, ))
247
247
userId=cur.fetchone()[0]
248
-
cur.execute("SELECT products.productId, products.name, products.price, products.image FROM products, kart WHERE products.productId = kart.productId AND kart.userId = "+str(userId))
248
+
cur.execute("SELECT products.productId, products.name, products.price, products.image FROM products, kart WHERE products.productId = kart.productId AND kart.userId = ?", (userId, ))
249
249
products=cur.fetchall()
250
250
totalPrice=0
251
251
forrowinproducts:
@@ -260,10 +260,10 @@ def removeFromCart():
260
260
productId=int(request.args.get('productId'))
261
261
withsqlite3.connect('database.db') asconn:
262
262
cur=conn.cursor()
263
-
cur.execute("SELECT userId FROM users WHERE email = '"+email+"'")
263
+
cur.execute("SELECT userId FROM users WHERE email = ?", (email, ))
264
264
userId=cur.fetchone()[0]
265
265
try:
266
-
cur.execute("DELETE FROM kart WHERE userId = "+str(userId) +" AND productId = "+str(productId))
266
+
cur.execute("DELETE FROM kart WHERE userId = ? AND productId = ?", (userId, productId))
0 commit comments