From 133ef9155d519f255bcfc48532542c426a5d6505 Mon Sep 17 00:00:00 2001 From: friendica Date: Mon, 18 Mar 2013 17:31:21 -0700 Subject: [PATCH] don't allow deleted accounts to appear on "manage" page --- include/security.php | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/include/security.php b/include/security.php index cb4587fbd..9f160e788 100644 --- a/include/security.php +++ b/include/security.php @@ -46,7 +46,7 @@ function authenticate_success($user_record, $login_initial = false, $interactive $master_record = $r[0]; } - $r = q("SELECT `uid`,`username`,`nickname` FROM `user` WHERE `password` = '%s' AND `email` = '%s'", + $r = q("SELECT `uid`,`username`,`nickname` FROM `user` WHERE `password` = '%s' AND `email` = '%s' AND `account_removed` = 0 ", dbesc($master_record['password']), dbesc($master_record['email']) ); @@ -56,8 +56,8 @@ function authenticate_success($user_record, $login_initial = false, $interactive $a->identities = array(); $r = q("select `user`.`uid`, `user`.`username`, `user`.`nickname` - from manage left join user on manage.mid = user.uid - where `manage`.`uid` = %d", + from manage left join user on manage.mid = user.uid where `user`.`account_removed` = 0 + and `manage`.`uid` = %d", intval($master_record['uid']) ); if($r && count($r))