Ignore:
Timestamp:
Feb 20, 2011, 1:14:40 PM (13 years ago)
Author:
patdenice
Message:

Use another $conf parameter to avoid conflicts.
Add htmlspecialchars in admin page.

File:
1 edited

Legend:

Unmodified
Added
Removed
  • extensions/AdditionalPages/admin/upgrade.inc.php

    r9310 r9323  
    1818}
    1919
    20 if ($conf['additional_pages'] === false)
     20if ($conf['AP'] === false)
    2121{
    2222  load_conf_from_db('param = "additional_pages"');
     
    6262    $position = $row['pos'];
    6363    if ($row['pos'] === '0')
    64       $position = '-100';
     64      $position = '-1000';
    6565    elseif (empty($row['pos']))
    6666      $position = '0';
     
    7070    $query = '
    7171UPDATE '.$prefixeTable.'additionalpages
    72 SET title = "'.addslashes($title).'",
     72SET title = "'.pwg_db_real_escape_string($title).'",
    7373    pos = '.$position.',
    7474    lang = '.$language.',
     
    108108  }
    109109
    110   $conf['additional_pages'] = $new_conf;
     110  $conf['AP'] = $new_conf;
    111111
    112112  conf_update_param('additional_pages', pwg_db_real_escape_string(serialize($new_conf)));
    113113}
    114114
    115 if (!isset($conf['additional_pages']['level_perm']))
     115if (!isset($conf['AP']['level_perm']))
    116116{
    117117  $query = '
     
    128128  pwg_query($query);
    129129
    130   $conf['additional_pages']['level_perm'] = false;
     130  $conf['AP']['level_perm'] = false;
    131131
    132   conf_update_param('additional_pages', pwg_db_real_escape_string(serialize($conf['additional_pages'])));
     132  conf_update_param('additional_pages', pwg_db_real_escape_string(serialize($conf['AP'])));
    133133}
    134134
Note: See TracChangeset for help on using the changeset viewer.