Changeset 1542 in ExiteCMS for trunk/themes/ExiteCMS/theme.php


Ignore:
Timestamp:
07/10/08 11:34:16 (4 years ago)
Author:
root
Message:

Fixed missing groupaccess() check in unread posts queries

File:
1 edited

Legend:

Unmodified
Added
Removed
  • trunk/themes/ExiteCMS/theme.php

    r1491 r1542  
    7070            SELECT count(*) as unread  
    7171                FROM ".$db_prefix."posts p  
     72                    INNER JOIN ".$db_prefix."forums f ON p.forum_id = f.forum_id  
    7273                    INNER JOIN ".$db_prefix."threads_read tr ON p.thread_id = tr.thread_id  
    73                 WHERE tr.user_id = '".$userdata['user_id']."'  
     74                WHERE ".groupaccess('f.forum_access')." 
     75                    AND tr.user_id = '".$userdata['user_id']."'  
    7476                    AND (p.post_datestamp > ".$settings['unread_threshold']." OR p.post_edittime > ".$settings['unread_threshold'].") 
    7577                    AND ((p.post_datestamp > tr.thread_last_read OR p.post_edittime > tr.thread_last_read) 
     
    8082            SELECT count(*) as unread  
    8183                FROM ".$db_prefix."posts p  
     84                    INNER JOIN ".$db_prefix."forums f ON p.forum_id = f.forum_id  
    8285                    INNER JOIN ".$db_prefix."threads_read tr ON p.thread_id = tr.thread_id  
    83                 WHERE tr.user_id = '".$userdata['user_id']."'  
     86                WHERE ".groupaccess('f.forum_access')." 
     87                    AND tr.user_id = '".$userdata['user_id']."'  
    8488                    AND p.post_author != '".$userdata['user_id']."' 
    8589                    AND p.post_edituser != '".$userdata['user_id']."' 
Note: See TracChangeset for help on using the changeset viewer.