fix two queries and corrected escaping of ticket-category, thx to vali

Signed-off-by: Michael Kaufmann (d00p) <d00p@froxlor.org>
This commit is contained in:
Michael Kaufmann (d00p)
2013-11-07 10:26:54 +01:00
parent 3e4697eb51
commit d251509beb
3 changed files with 10 additions and 3 deletions

View File

@@ -62,7 +62,11 @@ if ($page == 'overview' || $page == 'customers') {
WHERE `customerid` = :id" .
($userinfo['customers_see_all'] ? '' : " AND `adminid` = :adminid")
);
Database::pexecute($result_stmt, array('id' => $id, 'adminid' => $userinfo['adminid']));
$params = array('id' => $id);
if ($userinfo['customers_see_all'] == '0') {
$params['adminid'] = $userinfo['adminid'];
}
Database::pexecute($result_stmt, params);
$result = $result_stmt->fetch(PDO::FETCH_ASSOC);
if ($result['loginname'] != '') {