# HG changeset patch # User Franck Deroche # Date 1544658942 -3600 # Node ID e37ef9a817372ddba855d29fc93b097196edfbbe # Parent 1f2410012dbc09ad1cca9169735f6cc9415e5f3a# Parent efb93800fe10364aec72c63337fcbea6adb92408 Merge diff -r efb93800fe10 -r e37ef9a81737 comment.php --- a/comment.php Fri Nov 23 00:46:07 2018 +0100 +++ b/comment.php Thu Dec 13 00:55:42 2018 +0100 @@ -1,10 +1,10 @@ get('id'); // Enregistrement éventuel d'un commentaire dans la base de données $Auteur=$Req->get('Auteur'); diff -r efb93800fe10 -r e37ef9a81737 includes/class.dataaccess.php --- a/includes/class.dataaccess.php Fri Nov 23 00:46:07 2018 +0100 +++ b/includes/class.dataaccess.php Thu Dec 13 00:55:42 2018 +0100 @@ -74,6 +74,10 @@ function formatDate($timestamp, $decallage=2, $pattern='d/m/Y H:i:s') { return gmdate($pattern, $timestamp + $decallage * 3600); } + + function escapeString($string) { + return mysqli_escape_string($this->link, $string); + } function isInError() { diff -r efb93800fe10 -r e37ef9a81737 index.php --- a/index.php Fri Nov 23 00:46:07 2018 +0100 +++ b/index.php Thu Dec 13 00:55:42 2018 +0100 @@ -1,8 +1,11 @@ varSet('mode', 'GET')) { $query = " SELECT * FROM Mess @@ -11,10 +14,10 @@ LIMIT 10 "; $sk->setTitle('Dual { v10 : OS Edition } Blog'); - } elseif($_GET['mode'] == 'cal') { + } elseif($request->get('mode') == 'cal') { $sk->showCalendar(true); - $year = intval($_GET['year']); - $month = intval($_GET['month']); + $year = intval($request->get('year')); + $month = intval($request->get('month')); $sk->setCalendarMonth($month, $year); $sk->setTitle(TextUtils::getMonthName($month) . " $year - Dual Blog"); $query = " @@ -26,19 +29,18 @@ ORDER BY num_mess DESC LIMIT 10 "; - } elseif($_GET['mode'] == 'tag') { - $tag = $_GET['tag']; + } elseif($request->get('mode') == 'tag') { + $tag = $request->get('tag'); $sk->setTitle("Tag: $tag - Dual Blog"); $query = " SELECT * FROM Mess m LEFT JOIN Lien_Tags_Posts l ON m.num_mess=l.idMess LEFT JOIN Tags t ON l.idTag = t.idTag - WHERE t.Tag='{$_GET['tag']}' + WHERE t.Tag='{$tag}' ORDER BY num_mess DESC "; } - $db = Factory::getDB(); $db->query($query); while($row = $db->GetRow()) { $post = new Post($row);