From ec4adf8145e3466c95afb2b50139d835922e13f3 Mon Sep 17 00:00:00 2001 From: Nate Jones Date: Fri, 21 Feb 2014 04:22:25 +0000 Subject: [PATCH] Protected domain information from being overwritten. --- resources/switch.php | 11 ++++++++++- 1 file changed, 10 insertions(+), 1 deletion(-) diff --git a/resources/switch.php b/resources/switch.php index 9fa1903eff..22b29718cf 100644 --- a/resources/switch.php +++ b/resources/switch.php @@ -35,12 +35,21 @@ require_once "resources/require.php"; if (file_exists($_SERVER['DOCUMENT_ROOT'].PROJECT_PATH."/app/vars/app_config.php")) { if (strlen($_SESSION['user_defined_variables']) == 0) { $sql = "select * from v_vars "; - $sql .= "where var_cat = 'Defaults' "; + $sql .= "where var_cat = 'Defaults' and enabled = 'true' "; $prep_statement = $db->prepare(check_sql($sql)); $prep_statement->execute(); $result = $prep_statement->fetchAll(PDO::FETCH_ASSOC); foreach ($result as &$row) { switch ($row["var_name"]) { + case "domain": + //not allowed to override this value + break; + case "domain_name": + //not allowed to override this value + break; + case "domain_uuid": + //not allowed to override this value + break; case "username": //not allowed to override this value break;