Ignore:
Timestamp:
Nov 25, 2009, 8:02:57 PM (14 years ago)
Author:
nikrou
Message:

Feature 1255: modification in sql queries

  • manage random function
  • manage regex syntax
  • manage quote (single instead of double)
  • manage interval
File:
1 edited

Legend:

Unmodified
Added
Removed
  • trunk/include/functions_user.inc.php

    r4325 r4367  
    386386  ('.$userdata['id'].',\''.boolean_to_string($userdata['need_update']).'\','
    387387  .$userdata['cache_update_time'].',\''
    388   .$userdata['forbidden_categories'].'\','.$userdata['nb_total_images'].',"'
    389   .$userdata['image_access_type'].'","'.$userdata['image_access_list'].'")';
     388  .$userdata['forbidden_categories'].'\','.$userdata['nb_total_images'].',\''
     389  .$userdata['image_access_type'].'\',\''.$userdata['image_access_list'].'\')';
    390390      pwg_query($query);
    391391    }
     
    633633  if ( isset($filter_days) )
    634634  {
    635     $query .= ' AND i.date_available > SUBDATE(CURRENT_DATE,INTERVAL '.$filter_days.' DAY)';
     635    $query .= ' AND i.date_available > '.pwg_db_get_recent_period_expression($filter_days);
    636636  }
    637637
     
    10401040       '.$conf['user_fields']['password'].' AS password
    10411041  FROM '.USERS_TABLE.'
    1042   WHERE '.$conf['user_fields']['username'].' = \''.mysql_real_escape_string($username).'\'
     1042  WHERE '.$conf['user_fields']['username'].' = \''.pwg_db_real_escape_string($username).'\'
    10431043;';
    10441044  $row = pwg_db_fetch_assoc(pwg_query($query));
Note: See TracChangeset for help on using the changeset viewer.