Closed (fixed)
Project:
Views (for Drupal 7)
Version:
6.x-2.0-beta2
Component:
Code
Priority:
Normal
Category:
Bug report
Assigned:
Unassigned
Reporter:
Created:
8 May 2008 at 20:57 UTC
Updated:
3 Jun 2008 at 00:21 UTC
Jump to comment: Most recent file
Comments
Comment #1
bjaspan commentedAdd a comment explaining $q.
Comment #2
bjaspan commentedThe join code should also validate the input values before adding them to the SQL directly; too big a risk of an injection attack. Furthermore, the documentation should mention this loudly. I don't want to see an SA later in which a value from an argument gets used as an extra join value...
Comment #3
merlinofchaos commentedOk, patch cleaned up and committed, along with a method to ensure the type safety of the arguments. I think this could be cleaned up some more, even, but I'm ok with it the way it is for now.
It also goes the extra mile to replace IN () with = for single values, which always prettifies queries.
Comment #4
Anonymous (not verified) commentedAutomatically closed -- issue fixed for two weeks with no activity.