/[drupal]/contributions/modules/banner/banner.module
ViewVC logotype

Diff of /contributions/modules/banner/banner.module

Parent Directory Parent Directory | Revision Log Revision Log | View Revision Graph Revision Graph | View Patch Patch

revision 1.42, Mon Nov 1 03:07:08 2004 UTC revision 1.43, Wed Nov 24 22:03:32 2004 UTC
# Line 1  Line 1 
1  <?php  <?php
2  // $Id: banner.module,v 1.41 2004/10/30 19:46:56 jeremy Exp $  // $Id: banner.module,v 1.42 2004/11/01 03:07:08 jeremy Exp $
3    
4  function banner_help($section) {  function banner_help($section) {
5    switch($section) {    switch($section) {
# Line 468  function banner_user_save($edit) { Line 468  function banner_user_save($edit) {
468    $edit['uid'] = $user->uid;    $edit['uid'] = $user->uid;
469    
470    foreach ($fields as $field) {    foreach ($fields as $field) {
471      $values[] = (string)check_query($edit[$field]);      $values[] = (string)db_escape_string($edit[$field]);
472    }    }
473    
474    db_query('INSERT INTO {banner} (' .implode(', ', $fields). ") VALUES ('" .implode("', '", $values). "')");    db_query('INSERT INTO {banner} (' .implode(', ', $fields). ") VALUES ('" .implode("', '", $values). "')");
# Line 852  function banner_save($edit) { Line 852  function banner_save($edit) {
852    if ($edit['id']) {    if ($edit['id']) {
853      // update      // update
854      foreach ($fields as $field) {      foreach ($fields as $field) {
855        $update[] = "$field = '" .check_query($edit[$field]). "'";        $update[] = "$field = '" .db_escape_string($edit[$field]). "'";
856      }      }
857    
858      _banner_refresh_cache();      _banner_refresh_cache();
# Line 866  function banner_save($edit) { Line 866  function banner_save($edit) {
866      $edit['id'] = db_next_id('banner');      $edit['id'] = db_next_id('banner');
867    
868      foreach ($fields as $field) {      foreach ($fields as $field) {
869        $values[] = (string)check_query($edit[$field]);        $values[] = (string)db_escape_string($edit[$field]);
870      }      }
871    
872      db_query('INSERT INTO {banner} (' .implode(', ', $fields). ") VALUES ('" .implode("', '", $values). "')");      db_query('INSERT INTO {banner} (' .implode(', ', $fields). ") VALUES ('" .implode("', '", $values). "')");

Legend:
Removed from v.1.42  
changed lines
  Added in v.1.43

  ViewVC Help
Powered by ViewVC 1.1.2