| @@ -13,16 +13,23 @@ | ||
| 13 | 13 | * |
| 14 | 14 | * @since 1.0.0 |
| 15 | 15 | */ |
| 16 | 16 | function gamipress_wpforo_ajax_get_posts() { |
| 17 | + | |
| 17 | 18 | // Security check, forces to die if not security passed |
| 18 | 19 | check_ajax_referer( 'gamipress_admin', 'nonce' ); |
| 20 | + | |
| 21 | + // Check if user can manage GamiPress | |
| 22 | + if( ! current_user_can( gamipress_get_manager_capability() ) ) { | |
| 23 | + wp_send_json_error( __( 'You\'re not allowed to perform this action.', 'gamipress' ) ); | |
| 24 | + } | |
| 25 | + | |
| 19 | 26 | global $wpdb; |
| 20 | 27 | |
| 21 | 28 | if( isset( $_REQUEST['post_type'] ) ) { |
| 22 | 29 | |
| 23 | 30 | // Get the user input |
| 24 | - $search = isset( $_REQUEST['q'] ) ? $wpdb->esc_like( $_REQUEST['q'] ) : ''; | |
| 31 | + $search = isset( $_REQUEST['q'] ) ? $wpdb->esc_like( sanitize_text_field( $_REQUEST['q'] ) ) : ''; | |
| 25 | 32 | |
| 26 | 33 | if( in_array( 'wpforo_forum', $_REQUEST['post_type'] ) ) { |
| 27 | 34 | // Forums |
| 28 | 35 | |
| @@ -34,12 +41,17 @@ | ||
| 34 | 41 | "SELECT boardid FROM {$boards}" |
| 35 | 42 | ) ); |
| 36 | 43 | |
| 37 | 44 | // Try to find the forums |
| 38 | - $forums = $wpdb->get_results( $wpdb->prepare( | |
| 39 | - "SELECT * FROM {$table} | |
| 40 | - " . ( ! empty( $search ) ? "WHERE ( title LIKE '%{$search}%' OR title LIKE '{$search}%' )" : '' ) | |
| 41 | - ) ); | |
| 45 | + if ( ! empty( $search ) ) { | |
| 46 | + $forums = $wpdb->get_results( $wpdb->prepare( | |
| 47 | + "SELECT * FROM {$table} WHERE ( title LIKE %s OR title LIKE %s )", | |
| 48 | + "%%{$search}%%", | |
| 49 | + "{$search}%%" | |
| 50 | + ) ); | |
| 51 | + } else { | |
| 52 | + $forums = $wpdb->get_results( "SELECT * FROM {$table}" ); | |
| 53 | + } | |
| 42 | 54 | |
| 43 | 55 | // Build the results array |
| 44 | 56 | $results = array(); |
| 45 | 57 | |
| @@ -56,14 +68,20 @@ | ||
| 56 | 68 | if ( count( $results_boards ) > 1 ) { |
| 57 | 69 | foreach ( $results_boards as $board ){ |
| 58 | 70 | if ( $board->boardid !== '0' ){ |
| 59 | 71 | $table = $wpdb->prefix . 'wpforo_' . $board->boardid . '_forums'; |
| 60 | - // Get the forums | |
| 61 | - $results_forums = $wpdb->get_results( $wpdb->prepare( | |
| 62 | - "SELECT * FROM {$table} | |
| 63 | - " . ( ! empty( $search ) ? "WHERE ( title LIKE '%{$search}%' OR title LIKE '{$search}%' )" : '' ) | |
| 64 | - ) ); | |
| 65 | 72 | |
| 73 | + // Try to find the forums | |
| 74 | + if ( ! empty( $search ) ) { | |
| 75 | + $results_forums = $wpdb->get_results( $wpdb->prepare( | |
| 76 | + "SELECT * FROM {$table} WHERE ( title LIKE %s OR title LIKE %s )", | |
| 77 | + "%%{$search}%%", | |
| 78 | + "{$search}%%" | |
| 79 | + ) ); | |
| 80 | + } else { | |
| 81 | + $results_forums = $wpdb->get_results( "SELECT * FROM {$table}" ); | |
| 82 | + } | |
| 83 | + | |
| 66 | 84 | foreach ($results_forums as $forum ) { |
| 67 | 85 | $forum_id = $board->boardid . '-' . $forum->forumid; |
| 68 | 86 | $results[] = array( |
| 69 | 87 | 'ID' => $forum_id, |
| @@ -87,13 +105,19 @@ | ||
| 87 | 105 | $results_boards = $wpdb->get_results( $wpdb->prepare( |
| 88 | 106 | "SELECT boardid FROM {$boards}" |
| 89 | 107 | ) ); |
| 90 | 108 | |
| 91 | - // Try to find the topics | |
| 92 | - $topics = $wpdb->get_results( $wpdb->prepare( | |
| 93 | - "SELECT * FROM {$table} | |
| 94 | - " . ( ! empty( $search ) ? "WHERE ( title LIKE '%{$search}%' OR title LIKE '{$search}%' )" : '' ) | |
| 95 | - ) ); | |
| 109 | + // Try to find the forums | |
| 110 | + if ( ! empty( $search ) ) { | |
| 111 | + $topics = $wpdb->get_results( $wpdb->prepare( | |
| 112 | + "SELECT * FROM {$table} WHERE ( title LIKE %s OR title LIKE %s )", | |
| 113 | + "%%{$search}%%", | |
| 114 | + "{$search}%%" | |
| 115 | + ) ); | |
| 116 | + } else { | |
| 117 | + $topics = $wpdb->get_results( "SELECT * FROM {$table}" ); | |
| 118 | + } | |
| 119 | + | |
| 96 | 120 | |
| 97 | 121 | // Build the results array |
| 98 | 122 | $results = array(); |
| 99 | 123 | |
| @@ -111,13 +135,19 @@ | ||
| 111 | 135 | if ( count( $results_boards ) > 1 ) { |
| 112 | 136 | foreach ( $results_boards as $board ){ |
| 113 | 137 | if ( $board->boardid !== '0' ){ |
| 114 | 138 | $table = $wpdb->prefix . 'wpforo_' . $board->boardid . '_topics'; |
| 115 | - // Get the topics | |
| 116 | - $results_topics = $wpdb->get_results( $wpdb->prepare( | |
| 117 | - "SELECT * FROM {$table} | |
| 118 | - " . ( ! empty( $search ) ? "WHERE ( title LIKE '%{$search}%' OR title LIKE '{$search}%' )" : '' ) | |
| 119 | - ) ); | |
| 139 | + | |
| 140 | + // Try to find the topics | |
| 141 | + if ( ! empty( $search ) ) { | |
| 142 | + $results_topics = $wpdb->get_results( $wpdb->prepare( | |
| 143 | + "SELECT * FROM {$table} WHERE ( title LIKE %s OR title LIKE %s )", | |
| 144 | + "%%{$search}%%", | |
| 145 | + "{$search}%%" | |
| 146 | + ) ); | |
| 147 | + } else { | |
| 148 | + $results_topics = $wpdb->get_results( "SELECT * FROM {$table}" ); | |
| 149 | + } | |
| 120 | 150 | |
| 121 | 151 | foreach ($results_topics as $topic ) { |
| 122 | 152 | $forum_id = $board->boardid . '-' . $topic->forumid; |
| 123 | 153 | $results[] = array( |