security fix and ability to change layout on webpage edit form

This commit is contained in:
friendica
2013-09-03 16:31:59 -07:00
parent 0be8e4061c
commit 7b84b8480f
3 changed files with 60 additions and 43 deletions

View File

@@ -624,11 +624,12 @@ function item_post(&$a) {
if($orig_post) {
$r = q("UPDATE `item` SET `title` = '%s', `body` = '%s', `attach` = '%s', `edited` = '%s' WHERE `id` = %d AND `uid` = %d LIMIT 1",
$r = q("UPDATE `item` SET `title` = '%s', `body` = '%s', `attach` = '%s', `edited` = '%s', layout_mid = '%s' WHERE `id` = %d AND `uid` = %d LIMIT 1",
dbesc($datarray['title']),
dbesc($datarray['body']),
dbesc($datarray['attach']),
dbesc(datetime_convert()),
dbesc($layout_mid),
intval($post_id),
intval($profile_uid)
);