Fixed a problem with prepared statements.
authorJim Martens <jim1@live.de>
Wed, 19 Oct 2011 15:37:55 +0000 (17:37 +0200)
committerJim Martens <jim1@live.de>
Wed, 19 Oct 2011 15:37:55 +0000 (17:37 +0200)
wcfsetup/install/files/lib/data/user/UserEditor.class.php

index 39463d4a961420b2ff25738b85fce5fe548ed6a3..f3697a35b3cdfe12f4dc95b033ec8c5d48d3cc40 100644 (file)
@@ -158,8 +158,8 @@ class UserEditor extends DatabaseObjectEditor {
        public function addToGroup($groupID) {
                $sql = "SELECT  COUNT(*) AS count
                        FROM    wcf".WCF_N."_user_to_group
-                       WHERE   userID = ?".$this->userID."
-                               AND groupID = ?".$groupID;
+                       WHERE   userID = ?
+                               AND groupID = ?";
                $statement = WCF::getDB()->prepareStatement($sql);
                $statement->execute(array(
                        $this->userID,
@@ -191,7 +191,7 @@ class UserEditor extends DatabaseObjectEditor {
        
        /**
         * Removes a user from multiple user groups.
-        * 
+        *
         * @param       array           $groupIDs
         */
        public function removeFromGroups(array $groupIDs) {