summaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorMorris Jobke <hey@morrisjobke.de>2016-07-04 11:50:06 +0200
committerGitHub <noreply@github.com>2016-07-04 11:50:06 +0200
commitdd8af5c36d026ca5f0d205f09846a686ae9cc755 (patch)
treef49be5621a331046478e3e108073144140b4225d
parent42d8ef5a0efbac73d33af8c123f21afaf0204e20 (diff)
parentce70ea3501c23a2ca12cf6480e25cdec7664d02f (diff)
downloadnextcloud-server-dd8af5c36d026ca5f0d205f09846a686ae9cc755.tar.gz
nextcloud-server-dd8af5c36d026ca5f0d205f09846a686ae9cc755.zip
Merge pull request #298 from nextcloud/use-parameterized-query
[stable9] Use paramterized parameter for \OC\SystemTag\SystemTagManager
-rw-r--r--lib/private/systemtag/systemtagmanager.php5
1 files changed, 1 insertions, 4 deletions
diff --git a/lib/private/systemtag/systemtagmanager.php b/lib/private/systemtag/systemtagmanager.php
index 76a60a91328..51e605cc2fb 100644
--- a/lib/private/systemtag/systemtagmanager.php
+++ b/lib/private/systemtag/systemtagmanager.php
@@ -124,10 +124,7 @@ class SystemTagManager implements ISystemTagManager {
if (!empty($nameSearchPattern)) {
$query->andWhere(
- $query->expr()->like(
- 'name',
- $query->expr()->literal('%' . $this->connection->escapeLikeParameter($nameSearchPattern). '%')
- )
+ $query->expr()->like('name', $query->createNamedParameter('%' . $this->connection->escapeLikeParameter($nameSearchPattern) . '%'))
);
}