Merge pull request #298 from nextcloud/use-parameterized-query

[stable9] Use paramterized parameter for \OC\SystemTag\SystemTagManager
This commit is contained in:
Morris Jobke 2016-07-04 11:50:06 +02:00 committed by GitHub
commit dd8af5c36d
1 changed files with 1 additions and 4 deletions

View File

@ -124,10 +124,7 @@ class SystemTagManager implements ISystemTagManager {
if (!empty($nameSearchPattern)) {
$query->andWhere(
$query->expr()->like(
'name',
$query->expr()->literal('%' . $this->connection->escapeLikeParameter($nameSearchPattern). '%')
)
$query->expr()->like('name', $query->createNamedParameter('%' . $this->connection->escapeLikeParameter($nameSearchPattern) . '%'))
);
}