@@ -698,20 +698,7 @@ public function check_pop_moblog()
698698 preg_match ("/\<field\>(.*)\<\/field\>/s " , $ this ->body , $ matches ))) {
699699 $ matches [1 ] = trim ($ matches [1 ]);
700700
701- ee ()->db ->select ('field_id ' );
702- ee ()->db ->from ('channel_fields ' );
703- ee ()->db ->where ('(channel_fields.field_name = " ' . $ matches [1 ] . '" OR ' . ee ()->db ->dbprefix ('channel_fields ' ) . '.field_label = " ' . $ matches [1 ] . '") ' , null , false );
704-
705- /* -------------------------------------
706- /* Hidden Configuration Variable
707- /* - moblog_allow_nontextareas => Removes the textarea only restriction
708- /* for custom fields in the moblog module (y/n)
709- /* -------------------------------------*/
710- if (ee ()->config ->item ('moblog_allow_nontextareas ' ) != 'y ' ) {
711- ee ()->db ->where ('channel_fields.field_type ' , 'textarea ' );
712- }
713-
714- $ results = ee ()->db ->get ();
701+ $ results = $ this ->getFieldByNameOrLabel ($ matches [1 ], 'field_id ' );
715702
716703 if ($ results ->num_rows () > 0 ) {
717704 $ this ->moblog_array ['moblog_field_id ' ] = trim ($ results ->row ('field_id ' ));
@@ -1039,6 +1026,40 @@ public function assign_parameters($str)
10391026 return ee ('Variables/Parser ' )->parseTagParameters ($ str );
10401027 }
10411028
1029+ /**
1030+ * Look up a Moblog target field by name or label using bound values.
1031+ */
1032+ private function getFieldByNameOrLabel ($ field_name , $ select = 'field_id ' , $ group_id = null )
1033+ {
1034+ $ where = array ();
1035+ $ binds = array ();
1036+
1037+ if ($ group_id !== null ) {
1038+ $ where [] = 'group_id = ? ' ;
1039+ $ binds [] = $ group_id ;
1040+ }
1041+
1042+ $ where [] = '(field_name = ? OR field_label = ?) ' ;
1043+ $ binds [] = $ field_name ;
1044+ $ binds [] = $ field_name ;
1045+
1046+ /* -------------------------------------
1047+ /* Hidden Configuration Variable
1048+ /* - moblog_allow_nontextareas => Removes the textarea only restriction
1049+ /* for custom fields in the moblog module (y/n)
1050+ /* -------------------------------------*/
1051+ if (ee ()->config ->item ('moblog_allow_nontextareas ' ) != 'y ' ) {
1052+ $ where [] = 'field_type = ? ' ;
1053+ $ binds [] = 'textarea ' ;
1054+ }
1055+
1056+ $ sql = 'SELECT ' . $ select .
1057+ ' FROM ' . ee ()->db ->dbprefix ('channel_fields ' ) .
1058+ ' WHERE ' . implode (' AND ' , $ where );
1059+
1060+ return ee ()->db ->query ($ sql , $ binds );
1061+ }
1062+
10421063 /**
10431064 * parse_field
10441065 *
@@ -1064,17 +1085,7 @@ public function parse_field($params, $field_data)
10641085 $ format = ($ results ->num_rows () > 0 ) ? $ results ->row ('field_fmt ' ) : 'none ' ;
10651086 } else {
10661087 if ($ params ['name ' ] != '' && $ params ['format ' ] == '' ) {
1067- $ xsql = (ee ()->config ->item ('moblog_allow_nontextareas ' ) == 'y ' ) ? "" : " AND exp_channel_fields.field_type = 'textarea' " ;
1068-
1069- ee ()->db ->select ('field_id, field_fmt ' );
1070- ee ()->db ->where ('group_id ' , $ field_id );
1071- ee ()->db ->where ('(field_name = " ' . $ params ['name ' ] . '" OR field_label = " ' . $ params ['name ' ] . '") ' , null , false );
1072-
1073- if (ee ()->config ->item ('moblog_allow_nontextareas ' ) != 'y ' ) {
1074- ee ()->db ->where ('field_type ' , 'textarea ' );
1075- }
1076-
1077- $ results = ee ()->db ->get ('channel_fields ' );
1088+ $ results = $ this ->getFieldByNameOrLabel ($ params ['name ' ], 'field_id, field_fmt ' , $ field_id );
10781089
10791090 $ field_id = ($ results ->num_rows () > 0 ) ? $ results ->row ('field_id ' ) : $ this ->moblog_array ['moblog_field_id ' ];
10801091 $ format = ($ results ->num_rows () > 0 ) ? $ results ->row ('field_fmt ' ) : 'none ' ;
@@ -1091,16 +1102,7 @@ public function parse_field($params, $field_data)
10911102 $ field_id = $ this ->moblog_array ['moblog_field_id ' ];
10921103 $ format = $ params ['format ' ];
10931104 } elseif ($ params ['name ' ] != '' && $ params ['format ' ] != '' ) {
1094- $ xsql = (ee ()->config ->item ('moblog_allow_nontextareas ' ) == 'y ' ) ? "" : " AND exp_channel_fields.field_type = 'textarea' " ;
1095-
1096- ee ()->db ->select ('field_id ' );
1097- ee ()->db ->where ('(field_name = " ' . $ params ['name ' ] . '" OR field_label = " ' . $ params ['name ' ] . '") ' );
1098-
1099- if (ee ()->config ->item ('moblog_allow_nontextareas ' ) != 'y ' ) {
1100- ee ()->db ->where ('field_type ' , 'textarea ' );
1101- }
1102-
1103- $ results = ee ()->db ->get ('channel_fields ' );
1105+ $ results = $ this ->getFieldByNameOrLabel ($ params ['name ' ], 'field_id ' );
11041106
11051107 $ field_id = ($ results ->num_rows () > 0 ) ? $ results ->row ('field_id ' ) : $ this ->moblog_array ['moblog_field_id ' ];
11061108 $ format = $ params ['format ' ];
@@ -1595,7 +1597,9 @@ private function _process_attachment($value, $type, $subtype)
15951597 return true ;
15961598 }
15971599
1598- // Clean the file
1600+ // Clean decoded attachment content before raw_upload().
1601+ // EE_Upload is loaded below with explicit config, so its constructor
1602+ // does not enable the default xss_check() behavior for this path.
15991603 ee ()->load ->helper ('xss ' );
16001604
16011605 if (xss_check ()) {
@@ -1652,7 +1656,8 @@ private function _process_attachment($value, $type, $subtype)
16521656 $ file_path = ee ()->upload ->upload_path . $ filename ;
16531657 }
16541658
1655- // Disable xss cleaning in the filemanager
1659+ // The decoded attachment contents were cleaned above. Avoid a second
1660+ // File Manager XSS pass while registering the already-uploaded file.
16561661 ee ()->filemanager ->xss_clean_off ();
16571662
16581663 // Send the file
0 commit comments