Use prepareStatement() in UserStore.deleteUser() 48/103248/1
authorRobert Varga <robert.varga@pantheon.tech>
Wed, 16 Nov 2022 17:27:12 +0000 (18:27 +0100)
committerRobert Varga <robert.varga@pantheon.tech>
Wed, 16 Nov 2022 17:42:54 +0000 (18:42 +0100)
commit9c5c61991ac0dd1fb7d3f6b7bfed36eefe6f870d
tree3d4af714409d8e4a4863498dd46680427b9b8135
parentaa3596eae57d4a0c993305077938255055c9efca
Use prepareStatement() in UserStore.deleteUser()

The conversion to prepared statements has not dealt with the delete
function, leaving the ability to wipe the entire UserStore with SQL
injection. Fix this by using a proper prepared statement.

JIRA: AAA-241
Change-Id: Ie3d9a8eae815fab457809f3d2cd3577d38bd0207
Signed-off-by: Robert Varga <robert.varga@pantheon.tech>
(cherry picked from commit 9b912d4d433469b83f097fa76e203d7b97f44552)
aaa-idm-store-h2/src/main/java/org/opendaylight/aaa/datastore/h2/UserStore.java