Skip to:
Content

BuddyPress.org

Changeset 6518


Ignore:
Timestamp:
11/14/2012 08:04:09 PM (13 years ago)
Author:
djpaul
Message:

Fix more prepare() warnings. See #4654

Location:
trunk
Files:
2 edited

Legend:

Unmodified
Added
Removed
  • trunk/bp-friends/bp-friends-classes.php

    r6342 r6518  
    8585
    8686        if ( !empty( $friend_requests_only ) ) {
    87             $oc_sql = $wpdb->prepare( "AND is_confirmed = 0" );
    88             $friend_sql = $wpdb->prepare ( " WHERE friend_user_id = %d", $user_id );
    89         } else {
    90             $oc_sql = $wpdb->prepare( "AND is_confirmed = 1" );
    91             $friend_sql = $wpdb->prepare ( " WHERE (initiator_user_id = %d OR friend_user_id = %d)", $user_id, $user_id );
    92         }
    93 
    94         $friends = $wpdb->get_results( $wpdb->prepare( "SELECT friend_user_id, initiator_user_id FROM {$bp->friends->table_name} $friend_sql $oc_sql ORDER BY date_created DESC" ) );
     87            $oc_sql = 'AND is_confirmed = 0';
     88            $friend_sql = $wpdb->prepare( " WHERE friend_user_id = %d", $user_id );
     89        } else {
     90            $oc_sql = 'AND is_confirmed = 1';
     91            $friend_sql = $wpdb->prepare( " WHERE (initiator_user_id = %d OR friend_user_id = %d)", $user_id, $user_id );
     92        }
     93
     94        $friends = $wpdb->get_results( "SELECT friend_user_id, initiator_user_id FROM {$bp->friends->table_name} $friend_sql $oc_sql ORDER BY date_created DESC" );
    9595        $fids = array();
    9696
  • trunk/bp-xprofile/bp-xprofile-classes.php

    r6297 r6518  
    137137
    138138        if ( !empty( $hide_empty_groups ) )
    139             $groups = $wpdb->get_results( $wpdb->prepare( "SELECT DISTINCT g.* FROM {$bp->profile->table_name_groups} g INNER JOIN {$bp->profile->table_name_fields} f ON g.id = f.group_id {$where_sql} ORDER BY g.group_order ASC" ) );
     139            $groups = $wpdb->get_results( "SELECT DISTINCT g.* FROM {$bp->profile->table_name_groups} g INNER JOIN {$bp->profile->table_name_fields} f ON g.id = f.group_id {$where_sql} ORDER BY g.group_order ASC" );
    140140        else
    141             $groups = $wpdb->get_results( $wpdb->prepare( "SELECT DISTINCT g.* FROM {$bp->profile->table_name_groups} g {$where_sql} ORDER BY g.group_order ASC" ) );
     141            $groups = $wpdb->get_results( "SELECT DISTINCT g.* FROM {$bp->profile->table_name_groups} g {$where_sql} ORDER BY g.group_order ASC" );
    142142
    143143        if ( empty( $fetch_fields ) )
     
    171171
    172172        // Fetch the fields
    173         $fields = $wpdb->get_results( $wpdb->prepare( "SELECT id, name, description, type, group_id, is_required FROM {$bp->profile->table_name_fields} WHERE group_id IN ( {$group_ids} ) AND parent_id = 0 {$exclude_fields_sql} ORDER BY field_order" ) );
     173        $fields = $wpdb->get_results( "SELECT id, name, description, type, group_id, is_required FROM {$bp->profile->table_name_fields} WHERE group_id IN ( {$group_ids} ) AND parent_id = 0 {$exclude_fields_sql} ORDER BY field_order" );
    174174
    175175        if ( empty( $fields ) )
     
    331331        global $wpdb, $bp;
    332332
    333         $levels = $wpdb->get_results( $wpdb->prepare( "SELECT object_id, meta_key, meta_value FROM {$bp->profile->table_name_meta} WHERE object_type = 'field' AND ( meta_key = 'default_visibility' OR meta_key = 'allow_custom_visibility' )" ) );
     333        $levels = $wpdb->get_results( "SELECT object_id, meta_key, meta_value FROM {$bp->profile->table_name_meta} WHERE object_type = 'field' AND ( meta_key = 'default_visibility' OR meta_key = 'allow_custom_visibility' )" );
    334334
    335335        // Arrange so that the field id is the key and the visibility level the value
Note: See TracChangeset for help on using the changeset viewer.