]> git.wh0rd.org - tt-rss.git/commitdiff
API: getHeadlines: check for feed_id correctly
authorAndrew Dolgov <noreply@fakecake.org>
Wed, 29 Aug 2018 09:53:30 +0000 (12:53 +0300)
committerAndrew Dolgov <noreply@fakecake.org>
Wed, 29 Aug 2018 09:53:33 +0000 (12:53 +0300)
classes/api.php

index 5dbf8dc1ff6aaaab291f42ecc42ceab9977d0884..607a25e66ae9e0e9e8148c0a015c87dc8335ce24 100755 (executable)
@@ -11,7 +11,7 @@ class API extends Handler {
        static function param_to_bool($p) {
                return $p && ($p !== "f" && $p !== "false");
        }
-       
+
        function before($method) {
                if (parent::before($method)) {
                        header("Content-Type: text/json");
@@ -186,7 +186,7 @@ class API extends Handler {
 
        function getHeadlines() {
                $feed_id = clean($_REQUEST["feed_id"]);
-               if ($feed_id != "") {
+               if (is_int($feed_id)) {
 
                        if (is_numeric($feed_id)) $feed_id = (int) $feed_id;
 
@@ -293,8 +293,8 @@ class API extends Handler {
 
                        $article_qmarks = arr_qmarks($article_ids);
 
-                       $sth = $this->pdo->prepare("UPDATE ttrss_user_entries SET 
-                               $field = $set_to $additional_fields 
+                       $sth = $this->pdo->prepare("UPDATE ttrss_user_entries SET
+                               $field = $set_to $additional_fields
                                WHERE ref_id IN ($article_qmarks) AND owner_uid = ?");
                        $sth->execute(array_merge($article_ids, [$_SESSION['uid']]));
 
@@ -625,7 +625,7 @@ class API extends Handler {
                                        id, feed_url, cat_id, title, order_id, ".
                                                SUBSTRING_FOR_DATE."(last_updated,1,19) AS last_updated
                                                FROM ttrss_feeds WHERE
-                                               (cat_id = :cat OR (:cat = 0 AND cat_id IS NULL)) 
+                                               (cat_id = :cat OR (:cat = 0 AND cat_id IS NULL))
                                                AND owner_uid = :uid
                                                ORDER BY cat_id, title " . $limit_qpart);
                                $sth->execute([":uid" => $_SESSION['uid'], ":cat" => $cat_id]);