diff --git a/src/commands/faq.rs b/src/commands/faq.rs index 6da7bb0..4cc768b 100644 --- a/src/commands/faq.rs +++ b/src/commands/faq.rs @@ -39,16 +39,13 @@ async fn autocomplete_faq_titles<'a>( let server_guild_id = ctx.guild_id().expect("Guild ID not found"); let guild_id = server_guild_id.to_string(); move |conn| { - let mut stmt = conn.prepare(&format!( - "SELECT id, guild_id, title, description FROM faqs WHERE guild_id='{}'", - guild_id - ))?; + let mut stmt = conn.prepare( + "SELECT id, guild_id, title, description FROM faqs WHERE guild_id = ?1" + )?; let faqs: Vec = stmt - .query_map([], |row| { + .query_map([&guild_id], |row| { Ok(Faq { - // id: row.get(0)?, - // guild_id: row.get(1)?, title: row.get(2)?, description: row.get(3)?, }) @@ -91,13 +88,12 @@ pub async fn view( let guild_id = server_guild_id.to_string(); move |conn| { - let mut stmt = conn.prepare(&format!( - "SELECT id, guild_id, title, description FROM faqs WHERE title='{}' AND guild_id='{}'", - &faq_title, &guild_id - ))?; + let mut stmt = conn.prepare( + "SELECT id, guild_id, title, description FROM faqs WHERE title = ?1 AND guild_id = ?2" + )?; let faqs: Vec = stmt - .query_map([], |row| { + .query_map([&faq_title, &guild_id], |row| { Ok(Faq { // id: row.get(0)?, // guild_id: row.get(1)?,