mirror of
https://github.com/grocy/grocy.git
synced 2026-03-27 23:29:25 +01:00
Fixed a (theoretical, not practically relevant for the target use case of Grocy) SQL injection possibility (closes #2259)
This commit is contained in:
parent
297cc57244
commit
c415e2f8da
|
|
@ -892,7 +892,7 @@ class StockService extends BaseService
|
|||
return FindAllObjectsInArrayByPropertyValue($stockEntries, 'location_id', $locationId);
|
||||
}
|
||||
|
||||
public function GetProductStockLocations($productId, $allowSubproductSubstitution = false)
|
||||
public function GetProductStockLocations(int $productId, $allowSubproductSubstitution = false)
|
||||
{
|
||||
$sqlWhereProductId = 'product_id = ' . $productId;
|
||||
if ($allowSubproductSubstitution)
|
||||
|
|
|
|||
Loading…
Reference in New Issue
Block a user