function get_security_role($id)
{
- $sql = "SELECT * FROM ".TB_PREF."security_roles WHERE id='$id'";
+ $sql = "SELECT * FROM ".TB_PREF."security_roles WHERE id=".(int)$id;
$ret = db_query($sql, "could not retrieve security roles");
$row = db_fetch($ret);
if ($row != false) {
.",description=".db_escape($description)
.",sections=".db_escape(implode(';', $sections))
.",areas=".db_escape(implode(';', $areas))
- ." WHERE id=$id";
+ ." WHERE id=".(int)$id;
db_query($sql, "could not update role");
}
//--------------------------------------------------------------------------------------------------
function delete_security_role($id)
{
- $sql = "DELETE FROM ".TB_PREF."security_roles WHERE id=$id";
+ $sql = "DELETE FROM ".TB_PREF."security_roles WHERE id=".(int)$id;
db_query($sql, "could not delete role");
}
//--------------------------------------------------------------------------------------------------
function check_role_used($id) {
- $sql = "SELECT count(*) FROM ".TB_PREF."users WHERE role_id=$id";
+ $sql = "SELECT count(*) FROM ".TB_PREF."users WHERE role_id=".(int)$id;
$ret = db_query($sql, 'cannot check role usage');
$row = db_fetch($ret);
return $row[0];