]> gitweb.fluxo.info Git - lorea/elgg.git/commitdiff
Fixes #4432: Do not escape ORDER BY/GROUP BY clauses in elgg_get_entities
authorSteve Clay <steve@mrclay.org>
Tue, 17 Apr 2012 04:13:46 +0000 (00:13 -0400)
committerSteve Clay <steve@mrclay.org>
Tue, 17 Apr 2012 12:36:09 +0000 (08:36 -0400)
engine/lib/entities.php

index 4875b2c2f730a4649bcaa79cf595551f2738e08b..7fe9138881884d7d63942cb89e65765978c4add8 100644 (file)
@@ -915,11 +915,11 @@ function elgg_get_entities(array $options = array()) {
        }
 
        if (!$options['count']) {
-               if ($options['group_by'] = sanitise_string($options['group_by'])) {
+               if ($options['group_by']) {
                        $query .= " GROUP BY {$options['group_by']}";
                }
 
-               if ($options['order_by'] = sanitise_string($options['order_by'])) {
+               if ($options['order_by']) {
                        $query .= " ORDER BY {$options['order_by']}";
                }