X-Git-Url: https://git.wh0rd.org/?a=blobdiff_plain;f=plugins%2Fmail%2Finit.php;h=2897068aa5635598f85c75428cefe9b392be784e;hb=a42c55f02b7e313ab61bf826794d0888f2dceae1;hp=7adf36fe4540121c75f5c2cb3f375185d7d08f3d;hpb=72ff0137298f60970c664f0be24327b120bf4ac7;p=tt-rss.git diff --git a/plugins/mail/init.php b/plugins/mail/init.php index 7adf36fe..2897068a 100644 --- a/plugins/mail/init.php +++ b/plugins/mail/init.php @@ -28,13 +28,13 @@ class Mail extends Plugin { function emailArticle() { - $param = db_escape_string( $_REQUEST['param']); + $param = db_escape_string($_REQUEST['param']); print ""; print ""; print ""; - $result = db_query( "SELECT email, full_name FROM ttrss_users WHERE + $result = db_query("SELECT email, full_name FROM ttrss_users WHERE id = " . $_SESSION["uid"]); $user_email = htmlspecialchars(db_fetch_result($result, 0, "email")); @@ -56,7 +56,7 @@ class Mail extends Plugin { $tpl->setVariable('USER_EMAIL', $user_email, true); $tpl->setVariable('TTRSS_HOST', $_SERVER["HTTP_HOST"], true); - $result = db_query( "SELECT link, content, title + $result = db_query("SELECT link, content, title FROM ttrss_user_entries, ttrss_entries WHERE id = ref_id AND id IN ($param) AND owner_uid = " . $_SESSION["uid"]); @@ -147,7 +147,7 @@ class Mail extends Plugin { if (!$rc) { $reply['error'] = $mail->ErrorInfo; } else { - save_email_address( db_escape_string($destination)); + save_email_address(db_escape_string($destination)); $reply['message'] = "UPDATE_COUNTERS"; } @@ -155,7 +155,7 @@ class Mail extends Plugin { } function completeEmails() { - $search = db_escape_string( $_REQUEST["search"]); + $search = db_escape_string($_REQUEST["search"]); print "