diff options
author | Joas Schilling <nickvergessen@owncloud.com> | 2015-11-13 10:33:33 +0100 |
---|---|---|
committer | Joas Schilling <nickvergessen@owncloud.com> | 2015-11-30 17:12:48 +0100 |
commit | 2cdec74e8a1dd68f757ab89d64aeafac9e56d0ed (patch) | |
tree | 283ef6bec4c91880f3700d21e8db35dd8bf27d80 /apps/files/lib | |
parent | 623d34972dca25003d3f4107ec2715ff42bca086 (diff) | |
download | nextcloud-server-2cdec74e8a1dd68f757ab89d64aeafac9e56d0ed.tar.gz nextcloud-server-2cdec74e8a1dd68f757ab89d64aeafac9e56d0ed.zip |
Correctly escape the paths so we only display favorites instead of wildcards
Diffstat (limited to 'apps/files/lib')
-rw-r--r-- | apps/files/lib/activity.php | 2 |
1 files changed, 1 insertions, 1 deletions
diff --git a/apps/files/lib/activity.php b/apps/files/lib/activity.php index d473120b31f..c171b3bfabf 100644 --- a/apps/files/lib/activity.php +++ b/apps/files/lib/activity.php @@ -391,7 +391,7 @@ class Activity implements IExtension { } foreach ($favorites['folders'] as $favorite) { $fileQueryList[] = '`file` LIKE ?'; - $parameters[] = $favorite . '/%'; + $parameters[] = \OC::$server->getDatabaseConnection()->escapeLikeParameter($favorite) . '/%'; } return [ |