linkinfo: only allow to embed public items

This commit is contained in:
Mario Vavti 2019-08-11 10:55:38 +02:00
parent 047dd31724
commit f0d7a17b72

View File

@ -52,7 +52,7 @@ class Linkinfo extends \Zotlabs\Web\Controller {
if (!empty($mid) && $mid[1] == 'mid=b64.')
$mid[2] = base64_decode($mid[2]);
$r = q("SELECT id FROM item WHERE mid = '%s' AND uid = %d LIMIT 1",
$r = q("SELECT id FROM item WHERE mid = '%s' AND uid = %d AND item_private = 0 LIMIT 1",
dbesc((empty($mid) ? $url : $mid[2])),
intval(local_channel())
);