Closed (fixed)
Project:
Project issue tracking
Version:
5.x-2.x-dev
Component:
Issues
Priority:
Normal
Category:
Bug report
Assigned:
Reporter:
Created:
6 Sep 2007 at 22:06 UTC
Updated:
12 Oct 2007 at 21:51 UTC
Jump to comment: Most recent file
Comments
Comment #1
hunmonk commentedhm. i thought we had fixed this issue previously...
Comment #2
dwwnope, we never fixed this... we talked about it, but never actually worked on it.
Comment #3
hunmonk commentedi don't think there's a security risk here with removing the db_rewrite_sql(). we're loading up nodes and project comments internally and saving them back again. reviewing the code flow, i don't see any opportunities for any kind of attack vector, and there's no user output.
Comment #4
hunmonk commenteddrumm: hunmonk, eaton: there is a precedent for not using db_rewrite_sql on cron-- the search indexer
moshe_work: hunmonk: looks ok to me too
i believe enough of us agree to move forward with this approach... :)
attached was applied to 5.x-1.x, 4.7.x-1.x, 4.7.x-2.x
Comment #5
(not verified) commented