]> git.wh0rd.org Git - tt-rss.git/commitdiff
fix title/link quote escaping issue when subscribing from feed browser (thread 108)
authorAndrew Dolgov <fox@madoka.spb.ru>
Tue, 22 Aug 2006 07:17:40 +0000 (08:17 +0100)
committerAndrew Dolgov <fox@madoka.spb.ru>
Tue, 22 Aug 2006 07:17:40 +0000 (08:17 +0100)
backend.php

index 670ea4b59f4d9e9277b3779bebd93732cd4c432f..10f4b438c4588684f6290413b2bb7487c66acf79 100644 (file)
                                $result = db_query($link, "SELECT feed_url,title FROM ttrss_feeds
                                        WHERE id = '$id'");
 
-                               $feed_url = db_fetch_result($result, 0, "feed_url");
-                               $title = db_fetch_result($result, 0, "title");
+                               $feed_url = db_escape_string(db_fetch_result($result, 0, "feed_url"));
+                               $title = db_escape_string(db_fetch_result($result, 0, "title"));
+
+                               $title_orig = db_fetch_result($result, 0, "title");
 
                                $result = db_query($link, "SELECT id FROM ttrss_feeds WHERE
                                        feed_url = '$feed_url' AND owner_uid = " . $_SESSION["uid"]);
                                                "INSERT INTO ttrss_feeds (owner_uid,feed_url,title,cat_id) 
                                                VALUES ('".$_SESSION["uid"]."', '$feed_url', '$title', NULL)");
 
-                                       array_push($subscribed, $title);
+                                       array_push($subscribed, $title_orig);
                                }
                        }