svn: web/php-bugs/trunk/ bug.php rpc.php
| From: | Rasmus Lerdorf | Date: | Sun, 19 Jul 2009 23:19:40 +0000 |
| Subject: | svn: web/php-bugs/trunk/ bug.php rpc.php | ||
| Groups: | php.webmaster | ||
| Request: | Send a blank email to php-webmaster+get-5427@lists.php.net to get a copy of this message | ||
rasmus Sun, 19 Jul 2009 23:19:40 +0000
Revision: http://svn.php.net/viewvc?view=revision&revision=284395
Changed paths:
U web/php-bugs/trunk/bug.php
U web/php-bugs/trunk/rpc.php
Log:
Revert the mysql escaping here. We are unfortunately relying on
magic_quotes on this server. Hopefully the bug bug system will
be ready soon.
Modified: web/php-bugs/trunk/bug.php
===================================================================
--- web/php-bugs/trunk/bug.php 2009-07-19 22:46:03 UTC (rev 284394)
+++ web/php-bugs/trunk/bug.php 2009-07-19 23:19:40 UTC (rev 284395)
@@ -124,7 +124,7 @@
if (!$errors) {
$query = "INSERT INTO bugdb_comments (bug,email,ts,comment) VALUES"
- . " ('$id','" .
mysql_real_escape_string($in['commentemail']) .
"',NOW(),'".mysql_real_escape_string($ncomment)."')";
+ . "
('$id','{$in['commentemail']}',NOW(),'$ncomment')";
$success = @mysql_query($query);
}
$from = stripslashes($in['commentemail']);
@@ -160,12 +160,12 @@
if (!$errors && !($errors = incoming_details_are_valid($in))) {
/* update bug record */
- $query = "UPDATE bugdb SET sdesc='" .
mysql_real_escape_string($in['sdesc']) . "',status='" .
mysql_real_escape_string($in['status']) . "', bug_type='" .
mysql_real_escape_string($in['bug_type']) . "', php_version='" .
mysql_real_escape_string($in['php_version']) . "', php_os='" .
mysql_real_escape_string($in['php_os']) . "', ts2=NOW(),
email='".mysql_real_escape_string($from)."' WHERE id=$id";
+ $query = "UPDATE bugdb SET
sdesc='{$in['sdesc']}',status='{$in['status']}',
bug_type='{$in['bug_type']}',
php_version='{$in['php_version']}',
php_os='{$in['php_os']}', ts2=NOW(), email='$from' WHERE id=$id";
$success = @mysql_query($query);
/* add comment */
if ($success && !empty($ncomment)) {
- $query = "INSERT INTO bugdb_comments (bug, email, ts, comment) VALUES
($id,'".mysql_real_escape_string($from)."',NOW(),'".mysql_real_escape_string($ncomment)."')";
+ $query = "INSERT INTO bugdb_comments (bug, email, ts, comment) VALUES
($id,'$from',NOW(),'$ncomment)')";
$success = @mysql_query($query);
}
}
@@ -215,11 +215,11 @@
if (!$errors && !($errors = incoming_details_are_valid($in))) {
$query = 'UPDATE bugdb SET ';
- $query.= ($bug['email'] != $in['email'] &&
!empty($in['email'])) ? "email='" .
mysql_real_escape_string($in['email']) . "', " : '';
- $query.= "sdesc='".mysql_real_escape_string($in[sdesc])."',
status='".mysql_real_escape_string($in[status])."',
bug_type='".mysql_real_escape_string($in[bug_type])."',
assign='".mysql_real_escape_string($in[assign])."',
php_version='".mysql_real_escape_string($in[php_version])."',
php_os='".mysql_real_escape_string($in[php_os])."', ts2=NOW() WHERE
id=$id";
+ $query.= ($bug['email'] != $in['email'] &&
!empty($in['email'])) ? "email='{$in['email']}', " :
'';
+ $query.= "sdesc='{$in['sdesc']}',
status='{$in['status']}', bug_type='{$in['bug_type']}',
assign='{$in['assign']}',
php_version='{$in['php_version']}',
php_os='{$in['php_os']}', ts2=NOW() WHERE id=$id";
$success = @mysql_query($query);
if ($success && !empty($ncomment)) {
- $query = "INSERT INTO bugdb_comments (bug, email, ts, comment) VALUES
($id,'$user@php.net',NOW(),'".mysql_real_escape_string($ncomment)."')";
+ $query = "INSERT INTO bugdb_comments (bug, email, ts, comment) VALUES
($id,'$user@php.net',NOW(),'$ncomment')";
$success = @mysql_query($query);
}
Modified: web/php-bugs/trunk/rpc.php
===================================================================
--- web/php-bugs/trunk/rpc.php 2009-07-19 22:46:03 UTC (rev 284394)
+++ web/php-bugs/trunk/rpc.php 2009-07-19 23:19:40 UTC (rev 284395)
@@ -46,7 +46,7 @@
if(!empty($_POST['ncomment'])) {
$ncomment = trim($_POST['ncomment']);
- $query = "INSERT INTO bugdb_comments (bug,email,ts,comment) VALUES
('$id','$user@php.net',NOW(),'".mysql_real_escape_string($ncomment)."')";
+ $query = "INSERT INTO bugdb_comments (bug,email,ts,comment) VALUES
('$id','$user@php.net',NOW(),'$ncomment')";
$success = @mysql_query($query);
if($success) {
echo json_encode(array('result'=>array('status'=>$bug)));