Uploaded image for project: 'Moodle'
  1. Moodle
  2. MDL-64003

Messaging: Use sql_like_escape() to escape the search string in message_search_users()

    XMLWordPrintable

    Details

    • Type: Bug
    • Status: Closed
    • Priority: Minor
    • Resolution: Fixed
    • Affects Version/s: 3.6
    • Fix Version/s: 3.6.2
    • Component/s: Messages
    • Labels:
    • Testing Instructions:
      Hide
      1. As admin create 3 users: User1 = Amanda Something, User2 = A%a Something, User3 = Ama_da Something
      2. Click on message icon to open message interface
      3. Click on Search input
      4. Search for 'A%a' and check that there's only one user as result 
      5. Search for 'Ama_da' and check that there's only one user as result 
      Show
      As admin create 3 users: User1 = Amanda Something, User2 = A%a Something, User3 = Ama_da Something Click on message icon to open message interface Click on Search input Search for 'A%a' and check that there's only one user as result  Search for 'Ama_da' and check that there's only one user as result 
    • Affected Branches:
      MOODLE_36_STABLE
    • Fixed Branches:
      MOODLE_36_STABLE
    • Pull from Repository:
    • Pull Master Branch:
      MDL-64003-master

      Description

      Currently, you can use the special chars, like % and _ in the search, and we shouldn't be able to do this.

        Attachments

          Activity

            People

            Assignee:
            amaia Amaia Anabitarte
            Reporter:
            jaked Jake Dallimore
            Peer reviewer:
            Mark Nelson
            Integrator:
            Jake Dallimore
            Tester:
            Janelle Barcega
            Participants:
            Component watchers:
            Amaia Anabitarte, Carlos Escobedo, Ferran Recio, Sara Arjona (@sarjona), Víctor Déniz Falcón
            Votes:
            0 Vote for this issue
            Watchers:
            5 Start watching this issue

              Dates

              Created:
              Updated:
              Resolved:
              Fix Release Date:
              14/Jan/19

                Time Tracking

                Estimated:
                Original Estimate - 0 minutes
                0m
                Remaining:
                Remaining Estimate - 0 minutes
                0m
                Logged:
                Time Spent - 20 minutes
                20m