The addition of $cond into queries is not great since none of the strings inside the condition are being filtered. The risk is reduced by the nature of node machine names, but it would be ideal to do more filtering.

There's also no node_access in the D7 version. Since this module doesn't show data from the nodes, that's OK, but it could lead to situations where someone clicks "next" and gets nothing.

CommentFileSizeAuthor
#1 1736592_filtering_access.patch1.5 KBgreggles
Support from Acquia helps fund testing for Drupal Acquia logo

Comments

greggles’s picture

Status: Active » Needs work
FileSize
1.5 KB

This fixes one of the queries as an example and is totally untested.