diff --git a/lib/base/dao/dao.class.php b/lib/base/dao/dao.class.php
index 4fa1e1efc0..011ae686fa 100644
--- a/lib/base/dao/dao.class.php
+++ b/lib/base/dao/dao.class.php
@@ -1608,6 +1608,24 @@ class baseSQL
*/
public $conditionIsTrue = false;
+ /**
+ * 条件层级。
+ * The condition level.
+ *
+ * @var bool
+ * @access public;
+ */
+ public $conditionLevel = 0;
+
+ /**
+ * 条件结果,beginIF 中表达式的结果会存储到这个数组中。
+ * Store the result of the expression.
+ *
+ * @var bool
+ * @access public;
+ */
+ public $conditionResults = array();
+
/**
* WHERE条件嵌套小括号标记。
* If in mark or not.
@@ -1920,7 +1938,9 @@ class baseSQL
public function beginIF($condition)
{
$this->inCondition = true;
- $this->conditionIsTrue = $condition;
+ $this->conditionLevel += 1;
+ $this->conditionResults[$this->conditionLevel] = $condition;
+ $this->conditionIsTrue = !in_array(false, $this->conditionResults);
return $this;
}
@@ -1933,6 +1953,14 @@ class baseSQL
*/
public function fi()
{
+ unset($this->conditionResults[$this->conditionLevel]);
+ $this->conditionLevel -= 1;
+ if($this->conditionLevel > 0)
+ {
+ $this->conditionIsTrue = !in_array(false, $this->conditionResults);
+ return $this;
+ }
+
$this->inCondition = false;
$this->conditionIsTrue = false;
return $this;
@@ -1961,7 +1989,7 @@ class baseSQL
}
else
{
- $condition = ctype_alnum((string)$arg1) ? '`' . $arg1 . '`' : $arg1;
+ $condition = (is_string($arg1) && ctype_alnum($arg1)) ? '`' . $arg1 . '`' : $arg1;
}
if(!$this->inMark) $this->sql .= ' ' . DAO::WHERE ." $condition ";
@@ -1980,7 +2008,7 @@ class baseSQL
public function andWhere($condition, $addMark = false)
{
if($this->inCondition and !$this->conditionIsTrue) return $this;
- if(ctype_alnum((string)$condition)) $condition = '`' . $condition . '`';
+ if(is_string($condition) && ctype_alnum($condition)) $condition = '`' . $condition . '`';
$mark = $addMark ? '(' : '';
$this->sql .= " AND {$mark} $condition ";
@@ -1998,7 +2026,7 @@ class baseSQL
public function orWhere($condition)
{
if($this->inCondition and !$this->conditionIsTrue) return $this;
- if(ctype_alnum((string)$condition)) $condition = '`' . $condition . '`';
+ if(is_string($condition) && ctype_alnum($condition)) $condition = '`' . $condition . '`';
$this->sql .= " OR $condition ";
return $this;
diff --git a/lib/base/front/front.class.php b/lib/base/front/front.class.php
index ae59ad0497..1986a5118e 100644
--- a/lib/base/front/front.class.php
+++ b/lib/base/front/front.class.php
@@ -573,7 +573,14 @@ class baseHTML
}
}
- return "{$label}";
+ $button = "{$label}";
+
+ $app->loadClass('purifier', true);
+ $purifierConfig = HTMLPurifier_Config::createDefault();
+ $purifierConfig->set('Cache.DefinitionImpl', null);
+ $purifier = new HTMLPurifier($purifierConfig);
+
+ return $purifier->purify($button);
}
/**