X-Git-Url: https://git.mxchange.org/?a=blobdiff_plain;f=mod%2Ffsuggest.php;h=58bb11670070bbf22ceeee11fa1ede56c97b766c;hb=708ffaff51d3f5112af6b1fbd25d7ff6391e496e;hp=4f432d840a89287e5927214f3e190671c31cdd6e;hpb=27d94023eef0263a3ce9750f79a73ac941a25304;p=friendica.git diff --git a/mod/fsuggest.php b/mod/fsuggest.php index 4f432d840a..58bb116700 100644 --- a/mod/fsuggest.php +++ b/mod/fsuggest.php @@ -7,8 +7,9 @@ use Friendica\App; use Friendica\Core\ACL; use Friendica\Core\L10n; use Friendica\Core\Worker; -use Friendica\Database\DBM; +use Friendica\Database\DBA; use Friendica\Util\DateTimeFormat; +use Friendica\Util\Strings; function fsuggest_post(App $a) { @@ -22,47 +23,43 @@ function fsuggest_post(App $a) $contact_id = intval($a->argv[1]); - $r = q("SELECT * FROM `contact` WHERE `id` = %d AND `uid` = %d LIMIT 1", - intval($contact_id), - intval(local_user()) - ); - if (! DBM::is_result($r)) { + $contact = DBA::selectFirst('contact', [], ['id' => $contact_id, 'uid' => local_user()]); + if (! DBA::isResult($contact)) { notice(L10n::t('Contact not found.') . EOL); return; } - $contact = $r[0]; $new_contact = intval($_POST['suggest']); - $hash = random_string(); + $hash = Strings::getRandomHex(); - $note = escape_tags(trim($_POST['note'])); + $note = Strings::escapeHtml(trim(defaults($_POST, 'note', ''))); if ($new_contact) { $r = q("SELECT * FROM `contact` WHERE `id` = %d AND `uid` = %d LIMIT 1", intval($new_contact), intval(local_user()) ); - if (DBM::is_result($r)) { - $x = q("INSERT INTO `fsuggest` ( `uid`,`cid`,`name`,`url`,`request`,`photo`,`note`,`created`) + if (DBA::isResult($r)) { + q("INSERT INTO `fsuggest` ( `uid`,`cid`,`name`,`url`,`request`,`photo`,`note`,`created`) VALUES ( %d, %d, '%s','%s','%s','%s','%s','%s')", intval(local_user()), intval($contact_id), - dbesc($r[0]['name']), - dbesc($r[0]['url']), - dbesc($r[0]['request']), - dbesc($r[0]['photo']), - dbesc($hash), - dbesc(DateTimeFormat::utcNow()) + DBA::escape($contact['name']), + DBA::escape($contact['url']), + DBA::escape($contact['request']), + DBA::escape($contact['photo']), + DBA::escape($hash), + DBA::escape(DateTimeFormat::utcNow()) ); $r = q("SELECT `id` FROM `fsuggest` WHERE `note` = '%s' AND `uid` = %d LIMIT 1", - dbesc($hash), + DBA::escape($hash), intval(local_user()) ); - if (DBM::is_result($r)) { - $fsuggest_id = $r[0]['id']; + if (DBA::isResult($r)) { + $fsuggest_id = $contact['id']; q("UPDATE `fsuggest` SET `note` = '%s' WHERE `id` = %d AND `uid` = %d", - dbesc($note), + DBA::escape($note), intval($fsuggest_id), intval(local_user()) ); @@ -87,16 +84,11 @@ function fsuggest_content(App $a) $contact_id = intval($a->argv[1]); - $r = q( - "SELECT * FROM `contact` WHERE `id` = %d AND `uid` = %d LIMIT 1", - intval($contact_id), - intval(local_user()) - ); - if (! DBM::is_result($r)) { + $contact = DBA::selectFirst('contact', [], ['id' => $contact_id, 'uid' => local_user()]); + if (! DBA::isResult($contact)) { notice(L10n::t('Contact not found.') . EOL); return; } - $contact = $r[0]; $o = '

' . L10n::t('Suggest Friends') . '

';