From a7a937e180eaa5975b90594c49be4ca178ec4edb Mon Sep 17 00:00:00 2001 From: Akkariin Meiko Date: Tue, 21 Jan 2020 13:51:14 +0800 Subject: [PATCH] Fix: Query string escape bug --- api/index.php | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/api/index.php b/api/index.php index 4e55cae..3afe762 100755 --- a/api/index.php +++ b/api/index.php @@ -110,12 +110,12 @@ if((isset($_GET['apitoken']) && $_GET['apitoken'] == API_TOKEN) || (isset($_GET[ // 目前只验证域名和子域名 $domain = $_GET['domain'] ?? "null"; $subdomain = $_GET['subdomain'] ?? "null"; - $username = Database::escape($rs['username']); - $domain = Database::escape($domain); - $subdomain = Database::escape($subdomain); + $username = $rs['username']; + $domain = $domain; + $subdomain = $subdomain; $domainSQL = (isset($_GET['domain']) && !empty($_GET['domain'])) ? ["domain" => $domain] : ["subdomain" => $subdomain]; $querySQL = [ - "username" => $username, + "username" => $username, "proxy_type" => $proxyType ]; $querySQL = Array_merge($querySQL, $domainSQL);