[feladat @ 183]
Bugfix. When changing the username of an existing user, an sql error was shown due to bad quoting of a variable.
--- a/inc/users.inc.php Tue Mar 25 22:45:31 2008 +0000
+++ b/inc/users.inc.php Wed Mar 26 07:40:14 2008 +0000
@@ -275,7 +275,7 @@
// we have been given. User wants a change of username. Now, make
// sure it doesn't already exist.
- $query = "SELECT id FROM users WHERE username = " . $db->query($user);
+ $query = "SELECT id FROM users WHERE username = " . $db->quote($user);
$result = $db->query($query);
if (PEAR::isError($response)) { error($response->getMessage()); return false; }