Use service_id in the query to make it safer, also use named parameters

This commit is contained in:
Pea Tyczynska
2019-09-25 15:48:28 +01:00
parent 8cf8d24e37
commit c48aa77dd5
4 changed files with 19 additions and 7 deletions

View File

@@ -110,7 +110,7 @@ def get_all_notifications_for_service_job(service_id, job_id):
@job_blueprint.route('/<job_id>/notification_count', methods=['GET'])
def get_notification_count_for_job_id(service_id, job_id):
count = dao_get_notification_count_for_job_id(job_id)
count = dao_get_notification_count_for_job_id(service_id=service_id, job_id=job_id)
return jsonify(
count=count
), 200