diff --git a/app/access_controls/access_controls.php b/app/access_controls/access_controls.php index e3f0315167..c28da34c9d 100644 --- a/app/access_controls/access_controls.php +++ b/app/access_controls/access_controls.php @@ -1,4 +1,28 @@ + Portions created by the Initial Developer are Copyright (C) 2018 + the Initial Developer. All Rights Reserved. + + Contributor(s): + Mark J Crane +*/ //includes require_once "root.php"; @@ -55,7 +79,7 @@ $sql .= "limit $rows_per_page offset $offset "; $prep_statement = $db->prepare(check_sql($sql)); $prep_statement->execute(); - $result = $prep_statement->fetchAll(PDO::FETCH_NAMED); + $access_controls = $prep_statement->fetchAll(PDO::FETCH_NAMED); unset ($prep_statement, $sql); //alternate the row style @@ -91,27 +115,27 @@ echo "\n"; echo "\n"; - if (is_array($result)) { - foreach($result as $row) { + if (is_array($access_controls)) { + foreach($access_controls as $row) { if (permission_exists('access_control_edit')) { - $tr_link = "href='access_control_edit.php?id=".$row['access_control_uuid']."'"; + $tr_link = "href='access_control_edit.php?id=".escape($row['access_control_uuid'])."'"; } echo "\n"; - echo " ".$row['access_control_name']." \n"; - echo " ".$row['access_control_default']." \n"; - echo " ".$row['access_control_description']." \n"; + echo " ".escape($row['access_control_name'])." \n"; + echo " ".escape($row['access_control_default'])." \n"; + echo " ".escape($row['access_control_description'])." \n"; echo " "; if (permission_exists('access_control_edit')) { - echo "$v_link_label_edit"; + echo "$v_link_label_edit"; } if (permission_exists('access_control_delete')) { - echo "$v_link_label_delete"; + echo "$v_link_label_delete"; } echo " \n"; echo "\n"; if ($c==0) { $c=1; } else { $c=0; } } //end foreach - unset($sql, $result, $row_count); + unset($sql, $access_controls); } //end if results echo "\n"; @@ -138,4 +162,4 @@ //include the footer require_once "resources/footer.php"; -?> \ No newline at end of file +?>