Use query params for user strings

This commit is contained in:
Chase Tucker
2025-06-04 09:30:39 -07:00
parent 65a433e9ab
commit 4871668a90
2 changed files with 4 additions and 4 deletions

View File

@ -212,9 +212,9 @@ public class MRBService : IMRBService {
StringBuilder queryBuilder = new();
queryBuilder.Append("select (u.FirstName + ' ' + u.LastName) as OriginatorName, m.* ");
queryBuilder.Append("from MRB m join Users u on m.OriginatorID = u.UserID ");
queryBuilder.Append($"where m.Title = '{title}'");
queryBuilder.Append("where m.Title = @Title");
mrb = (await _dalService.QueryAsync<MRB>(queryBuilder.ToString())).FirstOrDefault();
mrb = (await _dalService.QueryAsync<MRB>(queryBuilder.ToString(), new { Title=title })).FirstOrDefault();
_cache.Set($"mrb{title}", mrb, DateTimeOffset.Now.AddHours(1));
}