improved search - ensure you can see all your own content (logged in members). Visitors can only see public wall posts.
This commit is contained in:
parent
34df1538f3
commit
3538dc15cc
|
@ -35,13 +35,9 @@ function search_content(&$a) {
|
||||||
if(! $search)
|
if(! $search)
|
||||||
return $o;
|
return $o;
|
||||||
|
|
||||||
|
// Here is the way permissions work in the search module...
|
||||||
$sql_extra = "
|
// Only public wall posts can be shown
|
||||||
AND `item`.`allow_cid` = ''
|
// OR your own posts if you are a logged in member
|
||||||
AND `item`.`allow_gid` = ''
|
|
||||||
AND `item`.`deny_cid` = ''
|
|
||||||
AND `item`.`deny_gid` = ''
|
|
||||||
";
|
|
||||||
|
|
||||||
$s_bool = "AND MATCH (`item`.`body`) AGAINST ( '%s' IN BOOLEAN MODE )";
|
$s_bool = "AND MATCH (`item`.`body`) AGAINST ( '%s' IN BOOLEAN MODE )";
|
||||||
$s_regx = "AND `item`.`body` REGEXP '%s' ";
|
$s_regx = "AND `item`.`body` REGEXP '%s' ";
|
||||||
|
@ -54,10 +50,10 @@ function search_content(&$a) {
|
||||||
$r = q("SELECT COUNT(*) AS `total`
|
$r = q("SELECT COUNT(*) AS `total`
|
||||||
FROM `item` LEFT JOIN `contact` ON `contact`.`id` = `item`.`contact-id`
|
FROM `item` LEFT JOIN `contact` ON `contact`.`id` = `item`.`contact-id`
|
||||||
WHERE `item`.`visible` = 1 AND `item`.`deleted` = 0
|
WHERE `item`.`visible` = 1 AND `item`.`deleted` = 0
|
||||||
AND ( `wall` = 1 OR `contact`.`uid` = %d )
|
AND (( `wall` = 1 AND `item`.`allow_cid` = '' AND `item`.`allow_gid` = '' AND `item`.`deny_cid` = '' AND `item`.`deny_gid` = '' )
|
||||||
|
OR `item`.`uid` = %d )
|
||||||
AND `contact`.`blocked` = 0 AND `contact`.`pending` = 0
|
AND `contact`.`blocked` = 0 AND `contact`.`pending` = 0
|
||||||
$search_alg
|
$search_alg ",
|
||||||
$sql_extra ",
|
|
||||||
intval(local_user()),
|
intval(local_user()),
|
||||||
dbesc($search)
|
dbesc($search)
|
||||||
);
|
);
|
||||||
|
@ -78,10 +74,10 @@ function search_content(&$a) {
|
||||||
FROM `item` LEFT JOIN `contact` ON `contact`.`id` = `item`.`contact-id`
|
FROM `item` LEFT JOIN `contact` ON `contact`.`id` = `item`.`contact-id`
|
||||||
LEFT JOIN `user` ON `user`.`uid` = `item`.`uid`
|
LEFT JOIN `user` ON `user`.`uid` = `item`.`uid`
|
||||||
WHERE `item`.`visible` = 1 AND `item`.`deleted` = 0
|
WHERE `item`.`visible` = 1 AND `item`.`deleted` = 0
|
||||||
AND ( `wall` = 1 OR `contact`.`uid` = %d )
|
AND (( `wall` = 1 AND `item`.`allow_cid` = '' AND `item`.`allow_gid` = '' AND `item`.`deny_cid` = '' AND `item`.`deny_gid` = '' )
|
||||||
|
OR `item`.`uid` = %d )
|
||||||
AND `contact`.`blocked` = 0 AND `contact`.`pending` = 0
|
AND `contact`.`blocked` = 0 AND `contact`.`pending` = 0
|
||||||
$search_alg
|
$search_alg
|
||||||
$sql_extra
|
|
||||||
ORDER BY `parent` DESC ",
|
ORDER BY `parent` DESC ",
|
||||||
intval(local_user()),
|
intval(local_user()),
|
||||||
dbesc($search)
|
dbesc($search)
|
||||||
|
|
Loading…
Reference in a new issue