From e0196d704fefe58bda01197e162a0924998c1e37 Mon Sep 17 00:00:00 2001 From: nicod_ <nicod@lerebooteux.fr> Date: Tue, 14 Nov 2023 22:19:01 +0100 Subject: [PATCH] =?UTF-8?q?fix:=20Caster,=20par=20s=C3=A9curit=C3=A9?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- action/ordonner_liens_blocks.php | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/action/ordonner_liens_blocks.php b/action/ordonner_liens_blocks.php index 8b325e8..f290b8f 100644 --- a/action/ordonner_liens_blocks.php +++ b/action/ordonner_liens_blocks.php @@ -20,8 +20,8 @@ function action_ordonner_liens_blocks_dist() { include_spip('action/editer_liens'); // objet lié - $objet_lie = objet_type(_request('objet_lie')); - $id_objet_lie = intval(_request('id_objet_lie')); + $objet_lie = objet_type((string)_request('objet_lie')); + $id_objet_lie = (int)_request('id_objet_lie'); // ordre des éléments $ordre = _request('ordre'); @@ -64,9 +64,9 @@ function action_ordonner_liens_blocks_dist() { foreach ($updates as $id => $ordre) { sql_updateq( 'spip_blocks', - ['rang_lien' => $ordre], + ['rang_lien' => (int)$ordre], [ - 'id_block = ' . $id, + 'id_block = ' . (int)$id, 'objet = ' . sql_quote($objet_lie), 'id_objet = ' . sql_quote($id_objet_lie), ] -- GitLab