diff options
author | Morris Jobke <hey@morrisjobke.de> | 2018-10-16 14:55:41 +0200 |
---|---|---|
committer | Morris Jobke <hey@morrisjobke.de> | 2018-10-16 15:24:02 +0200 |
commit | b458ed9c82eeca4eafb4e86b7774ceba90130838 (patch) | |
tree | 2f7187dd4de5c1ee7a83247759c6d3b975872aa7 /lib/private/Comments | |
parent | ad66b0f9ab010ee00d249d6f8512d30332e8a0af (diff) | |
download | nextcloud-server-b458ed9c82eeca4eafb4e86b7774ceba90130838.tar.gz nextcloud-server-b458ed9c82eeca4eafb4e86b7774ceba90130838.zip |
Properly escape column name in "createFunction" call
Signed-off-by: Morris Jobke <hey@morrisjobke.de>
Diffstat (limited to 'lib/private/Comments')
-rw-r--r-- | lib/private/Comments/Manager.php | 2 |
1 files changed, 1 insertions, 1 deletions
diff --git a/lib/private/Comments/Manager.php b/lib/private/Comments/Manager.php index 6d9e37ae94e..e9bb001f77d 100644 --- a/lib/private/Comments/Manager.php +++ b/lib/private/Comments/Manager.php @@ -163,7 +163,7 @@ class Manager implements ICommentsManager { */ protected function updateChildrenInformation($id, \DateTime $cDateTime) { $qb = $this->dbConn->getQueryBuilder(); - $query = $qb->select($qb->createFunction('COUNT(`id`)')) + $query = $qb->select($qb->createFunction('COUNT(' . $qb->getColumnName('id') . ')')) ->from('comments') ->where($qb->expr()->eq('parent_id', $qb->createParameter('id'))) ->setParameter('id', $id); |