Committed with db_escape instead of db_quote
[fa-stable.git] / manufacturing / includes / db / work_centres_db.inc
index a2255c3252f9ced4c8d5d84607108ab4d571261a..1338d5d0f091f771895ef481e1c2493633773237 100644 (file)
@@ -3,14 +3,14 @@
 function add_work_centre($name, $description)
 {
        $sql = "INSERT INTO ".TB_PREF."workcentres (name, description)
-               VALUES (".db_quote($name).",".db_quote($description).")";
+               VALUES (".db_escape($name).",".db_escape($description).")";
 
        db_query($sql, "could not add work centre");
 }
 
 function update_work_centre($type_id, $name, $description)
 {
-       $sql = "UPDATE ".TB_PREF."workcentres SET name=".db_quote($name).", description=".db_quote($description)."
+       $sql = "UPDATE ".TB_PREF."workcentres SET name=".db_escape($name).", description=".db_escape($description)."
                WHERE id=$type_id";
 
        db_query($sql, "could not update work centre");