Skip to content

Commit

Permalink
CONTRIB-6581 - Fixing use of double quotes in sql statements.
Browse files Browse the repository at this point in the history
  • Loading branch information
Mike Churchward authored and jamesmcq committed Jan 19, 2017
1 parent 06ace7b commit 1333521
Show file tree
Hide file tree
Showing 2 changed files with 4 additions and 4 deletions.
4 changes: 2 additions & 2 deletions classes/loginflow/rocreds.php
Expand Up @@ -42,8 +42,8 @@ protected function check_objects($o356username) {
$sql = 'SELECT u.username
FROM {local_o365_objects} obj
JOIN {user} u ON u.id = obj.moodleid
WHERE obj.o365name = ? and obj.type = "user"';
$params = [$o356username];
WHERE obj.o365name = ? and obj.type = ?';
$params = [$o356username, 'user'];
$user = $DB->get_record_sql($sql, $params);
}
return (!empty($user)) ? $user->username : $o356username;
Expand Down
4 changes: 2 additions & 2 deletions db/upgrade.php
Expand Up @@ -70,8 +70,8 @@ function xmldb_auth_oidc_upgrade($oldversion) {
tok.oidcusername as oidcusername
FROM {auth_oidc_token} tok
JOIN {user} u ON u.username = tok.username
WHERE u.auth = ? AND deleted = 0';
$params = ['oidc'];
WHERE u.auth = ? AND deleted = ?';
$params = ['oidc', 0];
$userstoupdate = $DB->get_recordset_sql($sql, $params);
foreach ($userstoupdate as $user) {
if (empty($user->idtoken)) {
Expand Down

0 comments on commit 1333521

Please sign in to comment.