diff --git a/lib/base/dao/dao.class.php b/lib/base/dao/dao.class.php index 4fa1e1efc0..011ae686fa 100644 --- a/lib/base/dao/dao.class.php +++ b/lib/base/dao/dao.class.php @@ -1608,6 +1608,24 @@ class baseSQL */ public $conditionIsTrue = false; + /** + * 条件层级。 + * The condition level. + * + * @var bool + * @access public; + */ + public $conditionLevel = 0; + + /** + * 条件结果,beginIF 中表达式的结果会存储到这个数组中。 + * Store the result of the expression. + * + * @var bool + * @access public; + */ + public $conditionResults = array(); + /** * WHERE条件嵌套小括号标记。 * If in mark or not. @@ -1920,7 +1938,9 @@ class baseSQL public function beginIF($condition) { $this->inCondition = true; - $this->conditionIsTrue = $condition; + $this->conditionLevel += 1; + $this->conditionResults[$this->conditionLevel] = $condition; + $this->conditionIsTrue = !in_array(false, $this->conditionResults); return $this; } @@ -1933,6 +1953,14 @@ class baseSQL */ public function fi() { + unset($this->conditionResults[$this->conditionLevel]); + $this->conditionLevel -= 1; + if($this->conditionLevel > 0) + { + $this->conditionIsTrue = !in_array(false, $this->conditionResults); + return $this; + } + $this->inCondition = false; $this->conditionIsTrue = false; return $this; @@ -1961,7 +1989,7 @@ class baseSQL } else { - $condition = ctype_alnum((string)$arg1) ? '`' . $arg1 . '`' : $arg1; + $condition = (is_string($arg1) && ctype_alnum($arg1)) ? '`' . $arg1 . '`' : $arg1; } if(!$this->inMark) $this->sql .= ' ' . DAO::WHERE ." $condition "; @@ -1980,7 +2008,7 @@ class baseSQL public function andWhere($condition, $addMark = false) { if($this->inCondition and !$this->conditionIsTrue) return $this; - if(ctype_alnum((string)$condition)) $condition = '`' . $condition . '`'; + if(is_string($condition) && ctype_alnum($condition)) $condition = '`' . $condition . '`'; $mark = $addMark ? '(' : ''; $this->sql .= " AND {$mark} $condition "; @@ -1998,7 +2026,7 @@ class baseSQL public function orWhere($condition) { if($this->inCondition and !$this->conditionIsTrue) return $this; - if(ctype_alnum((string)$condition)) $condition = '`' . $condition . '`'; + if(is_string($condition) && ctype_alnum($condition)) $condition = '`' . $condition . '`'; $this->sql .= " OR $condition "; return $this; diff --git a/lib/base/front/front.class.php b/lib/base/front/front.class.php index ae59ad0497..1986a5118e 100644 --- a/lib/base/front/front.class.php +++ b/lib/base/front/front.class.php @@ -573,7 +573,14 @@ class baseHTML } } - return "{$label}"; + $button = "{$label}"; + + $app->loadClass('purifier', true); + $purifierConfig = HTMLPurifier_Config::createDefault(); + $purifierConfig->set('Cache.DefinitionImpl', null); + $purifier = new HTMLPurifier($purifierConfig); + + return $purifier->purify($button); } /**