[Bug 1101] xarVarFetch() change Preparation and optional DB call
| Newsgroups | gmane.comp.cms.xaraya.bugs |
|---|---|
| Message-ID | <[email protected]> |
http://bugs.xaraya.com/show_bug.cgi?id=1101 [email protected] changed: What |Removed |Added ---------------------------------------------------------------------------- Keywords| |VERIFY_NEEDED Summary|Change variable escaping |xarVarFetch() change |from the input |Preparation and optional DB |API(xarVarFetch) to the |call |output API (BL) | ------- Comment #5 from [email protected] 2009-03-15 08:55 GMT ------- Subject was: Change variable escaping from the input API(xarVarFetch) to the output API (BL) Jason in mt-notices: >> Changelog: >> xarVarFetch - Bug 1101: Removing DB call >> Preparation affects now all values independent from source (URL, old and > > I haven't tested this out, but isn't this change now going to potentially > double-XML encode submitted items on a form containing errors? > > In addition, the DB connection object is only used if it is needed, not every > time the xarVarFetch() is called up. The database is not even accessed anyway > when the prepare is done - it is just a call to the global connection object. I searched the code of some common modules and did not found this flag. > At first glance though, this is probably the wrong place to do both DB preps and > display preps. The trim can be done via a validation rule. The prep stuff could > probably be removed altogether. They can all become chainable validation rules > if someone still wants that functionality. I agree on the double trim options. Set VERIFY_NEEDED, see: > http://mt.xaraya.com/revision/diff/f15fdd21e06a52badc9af23bbc0829e688112a75/with/e9bb89f5212c2af7429c91bd9669f5c8b9cd3923/html/includes/xarVar.php -- Configure bugmail: http://bugs.xaraya.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug, or are watching someone who is. ---- ** IMPORTANT ** READ BELOW ** ---- [Clip Me Start] -------------------------------------------------------------------------- If you wish, you can reply to this message directly **however**, make sure to use the "Reply To All" feature of your client **and** ensure that the bug specifier is in the subject (ie: [Bug ####]). Also, you _MUST_ have you're From or Reply-To address set to the same address you use to log into your bugzilla account or your reply will not be attached to the bug. -------------------------------------------------------------------------- [Clip Me End]