Uploaded image for project: 'In-Portal CMS'
  1. In-Portal CMS
  2. INP-958

Improvement of "qstr" function

    XMLWordPrintable

    Details

      Description

      In-Portal uses "kDBConnection::qstr" function to escape user request variables before placing their values into database. This prevents sql injections.

      However there are cases, when there is a need to escape whole array of values.

      I've created kDBConnection:qstrArray function that easily allows to do that.

        Attachments

          Issue Links

            Activity

              People

              • Assignee:
                alex Alex
                Reporter:
                alex Alex
                Developer:
                Alex
              • Votes:
                0 Vote for this issue
                Watchers:
                0 Start watching this issue

                Dates

                • Created:
                  Updated:
                  Resolved: