Changeset 1324

Show
Ignore:
Timestamp:
12/02/07 23:03:10 (1 year ago)
Author:
ewout
Message:

Avoid a database error and validate file widget data. Fixes #149

Files:

Legend:

Unmodified
Added
Removed
Modified
Copied
Moved
  • devel/mod/file/lib.php

    r1248 r1324  
    307307function file_widget_display($widget) { 
    308308    global $CFG; 
    309     $latest_files = widget_get_data("latest_files",$widget->ident); 
     309    $latest_files = clean_param(widget_get_data("latest_files",$widget->ident),PARAM_INT); 
    310310    $html = "<p>" . __gettext("No files found.") . "</p>"; 
    311311    if ($widget->type == "file::files") { 
     
    339339 
    340340function file_widget_edit($widget) { 
    341     $latest_files = widget_get_data("latest_files",$widget->ident); 
     341    $latest_files = clean_param(widget_get_data("latest_files",$widget->ident),PARAM_INT); 
    342342    $body = ""; 
    343343    $body = "<h2>" . __gettext("Files widget") . "</h2>";