Changeset 1003
- Timestamp:
- 04/23/08 17:27:48 (6 months ago)
- Files:
-
- traduc/trunk/www/search.php (modified) (4 diffs)
Legend:
- Unmodified
- Added
- Removed
- Modified
- Copied
- Moved
traduc/trunk/www/search.php
r994 r1003 50 50 <form method="post" action="search.php"> 51 51 <div> 52 <input id="q" name="q" type="text" size="20" maxlength="255" onfocus="if( this.value=='Rechercher' ) this.value='';" value="<?= strlen($_POST['q'])>0 ? $_POST['q'] : 'Rechercher' ?>" accesskey="s" /><input id="submit" name="submit" type="submit" value="Rechercher" /> 52 <input id="q" name="q" type="text" size="20" maxlength="255" onfocus="if( this.value=='Rechercher' ) this.value='';" value="<?= strlen($_POST['q'])>0 ? $_POST['q'] : 'Rechercher' ?>" accesskey="s" /> 53 <input id="submit" name="submit" type="submit" value="Rechercher" /> 53 54 <select id="v" name="v"> 54 55 <? … … 72 73 </form> 73 74 <? 74 $recherche = $_POST['q'];75 $recherche = pg_escape_string($_POST['q']); 75 76 76 77 $query = "SELECT version, url, titre … … 78 79 WHERE (url like 'sql-%".ereg_replace(' ','',$recherche)."%.html' OR url like 'app-%".ereg_replace('_','',$recherche)."%.html' OR url like 'app-%".ereg_replace('_','-',$recherche)."%.html') "; 79 80 if ($filtreversion > 0) 80 $query .= "AND version=". $filtreversion." ";81 $query .= "AND version=".pg_escape_string($filtreversion)." "; 81 82 $query .= "ORDER BY version desc, titre "; 82 83 $result = pg_query($pgconn, $query); … … 168 169 WHERE fti @@ q "; 169 170 if ($filtreversion > 0) 170 $query .= "AND version=". $filtreversion." ";171 $query .= "AND version=".pg_escape_string($filtreversion)." "; 171 172 $query .= "ORDER BY ts_rank(fti, q) DESC 172 173 LIMIT 100";

