comparison recomplete.php @ 16:cf19005e65d1

added: mysql_real_escape_string
author Sushi-k <epgrec@park.mda.or.jp>
date Wed, 15 Jul 2009 13:02:20 +0900
parents b0fc647167f5
children 19bd80c60009
comparison
equal deleted inserted replaced
15:cbbddf99d1cd 16:cf19005e65d1
9 $rrec = new DBRecord( TBL_PREFIX.RESERVE_TBL, "id" , $reserve_id ); 9 $rrec = new DBRecord( TBL_PREFIX.RESERVE_TBL, "id" , $reserve_id );
10 10
11 if( file_exists( INSTALL_PATH . SPOOL . "/". $rrec->path ) ) { 11 if( file_exists( INSTALL_PATH . SPOOL . "/". $rrec->path ) ) {
12 // 予約完了 12 // 予約完了
13 $rrec->complete = '1'; 13 $rrec->complete = '1';
14 if( MEDIATOMB_UPDATE) { 14 if( defined(MEDIATOMB_UPDATE) ) {
15 $dbh = mysql_connect( DB_HOST, DB_USER, DB_PASS ); 15 if( MEDIATOMB_UPDATE ) {
16 if( $dbh !== false ) { 16 $dbh = mysql_connect( DB_HOST, DB_USER, DB_PASS );
17 $sqlstr = "use ".DB_NAME; 17 if( $dbh !== false ) {
18 mysql_query( $sqlstr ); 18 $sqlstr = "use ".DB_NAME;
19 // 別にやらなくてもいいが 19 mysql_query( $sqlstr );
20 $sqlstr = "set NAME utf8"; 20 // 別にやらなくてもいいが
21 mysql_query( $sqlstr ); 21 $sqlstr = "set NAME utf8";
22 $sqlstr = "update mt_cds_object set metadata='dc:description=".$rrec->description."' where dc_title='".$rrec->path."'"; 22 mysql_query( $sqlstr );
23 mysql_query( $sqlstr ); 23 $sqlstr = "update mt_cds_object set metadata='dc:description=".mysql_real_escape_string($rrec->description)."' where dc_title='".$rrec->path."'";
24 $sqlstr = "update mt_cds_object set dc_title='".$rrec->title."(".date("Y/m/d").")' where dc_title='".$rrec->path."'"; 24 mysql_query( $sqlstr );
25 mysql_query( $sqlstr ); 25 $sqlstr = "update mt_cds_object set dc_title='".mysql_real_escape_string($rrec->title)."(".date("Y/m/d").")' where dc_title='".$rrec->path."'";
26 mysql_query( $sqlstr );
27 }
26 } 28 }
27 } 29 }
28 } 30 }
29 else { 31 else {
30 // 予約失敗 32 // 予約失敗
31 $rrec->delete(); 33 $rrec->delete();
32 } 34 }