$error=$error_messages['EVENT_PERMISSION_ERROR'];
return false;
}
- $bans=explode(";",$_POST['bans']);
+ $bans=explode(";",$_POST['bans']); // XXX sqli?
$db->query("update node_access set node_permission='' where node_id=$node_id and node_permission='ban'");
foreach ($bans as $ban) {
$q="insert into node_access set node_permission='ban',node_id=$node_id,user_id=".$set->getString('user_id');
$db->query($q);
}
- $log->log('add ban',$node_id,'ok',$ban);
+ logger::log('add ban',$node_id,'ok',$ban);
}
else { $error .= "$ban does not exist..."; }
}