diff --git a/lib/dbwrap.js b/lib/dbwrap.js index 874fa03..56a2d83 100644 --- a/lib/dbwrap.js +++ b/lib/dbwrap.js @@ -104,7 +104,7 @@ function wrap(db, dir) { if (i !== 0) { sql += 'AND '; } - sql += db.escape(snakeCase(key)) + ' ' + db.escape(opts[key]); + sql += db.escape(snakeCase(key)) + " = '" + db.escape(opts[key]) + "'"; }); if (params) { @@ -116,7 +116,7 @@ function wrap(db, dir) { } } - return db.allAsync("SELECT * FROM " + tablename + " " + sql, []).then(simpleMap); + return db.allAsync(sql, []).then(simpleMap); }; DB.get = function (id) {