]> source.dussan.org Git - nextcloud-server.git/commitdiff
Correctly escape the paths so we only display favorites instead of wildcards
authorJoas Schilling <nickvergessen@owncloud.com>
Fri, 13 Nov 2015 09:33:33 +0000 (10:33 +0100)
committerJoas Schilling <nickvergessen@owncloud.com>
Mon, 30 Nov 2015 16:12:48 +0000 (17:12 +0100)
apps/files/lib/activity.php

index d473120b31fc946ad13c39187c93f4f2b0ab2b48..c171b3bfabf160ba2bc612920e1b7f28255efcaa 100644 (file)
@@ -391,7 +391,7 @@ class Activity implements IExtension {
                        }
                        foreach ($favorites['folders'] as $favorite) {
                                $fileQueryList[] = '`file` LIKE ?';
-                               $parameters[] = $favorite . '/%';
+                               $parameters[] = \OC::$server->getDatabaseConnection()->escapeLikeParameter($favorite) . '/%';
                        }
 
                        return [