diff options
author | Friendika <info@friendika.com> | 2011-03-04 20:55:32 -0800 |
---|---|---|
committer | Friendika <info@friendika.com> | 2011-03-04 20:55:32 -0800 |
commit | 216f038456cae1016e030b33cac79f8ed690e366 (patch) | |
tree | 3db6bdcb57a3e68f24f7366da5d966a60bbb51a1 /mod | |
parent | 3c076b53fe0fb3d5e625b773a5e4723dece0a057 (diff) | |
download | volse-hubzilla-216f038456cae1016e030b33cac79f8ed690e366.tar.gz volse-hubzilla-216f038456cae1016e030b33cac79f8ed690e366.tar.bz2 volse-hubzilla-216f038456cae1016e030b33cac79f8ed690e366.zip |
icon changes, feed security improvements
Diffstat (limited to 'mod')
-rw-r--r-- | mod/pubsub.php | 11 | ||||
-rw-r--r-- | mod/wall_upload.php | 4 |
2 files changed, 10 insertions, 5 deletions
diff --git a/mod/pubsub.php b/mod/pubsub.php index df27c6bc2..5d8ea2ed7 100644 --- a/mod/pubsub.php +++ b/mod/pubsub.php @@ -55,7 +55,8 @@ function pubsub_init(&$a) { $sql_extra = ((strlen($hub_verify)) ? sprintf(" AND `hub-verify` = '%s' ", dbesc($hub_verify)) : ''); - $r = q("SELECT * FROM `contact` WHERE `poll` = '%s' AND `id` = %d AND `uid` = %d AND `blocked` = 0 $sql_extra LIMIT 1", + $r = q("SELECT * FROM `contact` WHERE `poll` = '%s' AND `id` = %d AND `uid` = %d + AND `blocked` = 0 AND `pending` = 0 $sql_extra LIMIT 1", dbesc($hub_topic), intval($contact_id), intval($owner['uid']) @@ -101,10 +102,14 @@ function pubsub_post(&$a) { $importer = $r[0]; - $r = q("SELECT * FROM `contact` WHERE `subhub` = 1 AND `id` = %d AND `uid` = %d AND `blocked` = 0 AND `readonly` = 0 LIMIT 1", + $r = q("SELECT * FROM `contact` WHERE `subhub` = 1 AND `id` = %d AND `uid` = %d + AND ( `rel` = %d OR `rel` = %d ) AND `blocked` = 0 AND `readonly` = 0 LIMIT 1", intval($contact_id), - intval($importer['uid']) + intval($importer['uid']), + intval(REL_FAN), + intval(REL_BUD) ); + if(! count($r)) { logger('pubsub: no contact record - ignored'); hub_post_return(); diff --git a/mod/wall_upload.php b/mod/wall_upload.php index ab06b4b2d..b5725311d 100644 --- a/mod/wall_upload.php +++ b/mod/wall_upload.php @@ -101,5 +101,5 @@ function wall_upload_post(&$a) { echo '<br /><br /><a href="' . $a->get_baseurl() . '/photos/' . $page_owner_nick . '/image/' . $hash . '" ><img src="' . $a->get_baseurl() . "/photo/{$hash}-{$smallest}.jpg\" alt=\"$basename\" /></a><br /><br />"; killme(); - return; // NOTREACHED -}
\ No newline at end of file + // NOTREACHED +} |