PluginProbe
Yatra – Travel Booking & Tour Operator Software / 3.0.16
Yatra – Travel Booking & Tour Operator Software v3.0.16
3.0.16 3.0.15 3.0.14 3.0.14.1 3.0.14.2 3.0.12 3.0.13 3.0.11 3.0.10 3.0.9 3.0.8 3.0.7 3.0.6 3.0.5 3.0.5.1 3.0.4 3.0.3 3.0.2.9 3.0.2.7 3.0.2.8 3.0.2.6 trunk 1.0.0 2.0.0 2.0.1 All 84 releases
← All changes | app/Repositories/EnquiryRepository.php +8 -6 3.0.2.6 → 3.0.16 View file →
@@ -27,11 +27,10 @@
27 27 * Get trips table name
28 28 */
29 29 protected function getTripsTable(): string
30 30 {
31 - // Use TripRepository for trips table
32 - $tripRepository = new \Yatra\Repositories\TripRepository();
33 - return $tripRepository->getTableName();
31 + // Avoid relying on TripRepository visibility/overrides; use the canonical table class.
32 + return \Yatra\Database\Tables\TripsTable::getTableName();
34 33 }
35 34
36 35 /**
37 36 * Get paginated enquiries with filters
@@ -398,11 +397,14 @@
398 397 if (array_key_exists('phone', $data)) {
399 398 $prepared['phone'] = sanitize_text_field((string) $data['phone']);
400 399 }
401 400
402 - if (array_key_exists('subject', $data)) {
403 - $prepared['subject'] = sanitize_text_field((string) $data['subject']);
404 - }
401 + // NOTE: no `subject` mapping. The enquiries table has never had a
402 + // `subject` column, so writing one made $wpdb reject the whole INSERT /
403 + // UPDATE — and create() turns that into an exception, which the public
404 + // POST /enquiries endpoint surfaced as a 500 carrying the raw SQL error.
405 + // Any caller that sends `subject` is now simply ignored, as it always
406 + // effectively was for reads.
405 407
406 408 if (array_key_exists('message', $data)) {
407 409 $prepared['message'] = sanitize_textarea_field((string) $data['message']);
408 410 }