Skip to content

Commit

Permalink
Correct Mangling of Special Characters
Browse files Browse the repository at this point in the history
  • Loading branch information
geoffhumphrey committed Feb 18, 2021
1 parent 28b6ffd commit 69daa47
Show file tree
Hide file tree
Showing 11 changed files with 56 additions and 56 deletions.
2 changes: 1 addition & 1 deletion includes/process/process_brewer.inc.php
Original file line number Diff line number Diff line change
Expand Up @@ -637,7 +637,7 @@

if (isset($_POST['userQuestionAnswer'])) {
$userQuestionAnswer = $purifier->purify($_POST['userQuestionAnswer']);
$userQuestionAnswer = filter_var($userQuestionAnswer,FILTER_SANITIZE_STRING,FILTER_FLAG_ENCODE_HIGH|FILTER_FLAG_ENCODE_LOW);
$userQuestionAnswer = filter_var($userQuestionAnswer,FILTER_SANITIZE_STRING);
$updateSQL = sprintf("UPDATE $users_db_table SET userQuestionAnswer=%s WHERE id=%s",GetSQLValueString($userQuestionAnswer,"text"),GetSQLValueString($_SESSION['user_id'],"int"));
mysqli_real_escape_string($connection,$updateSQL);
$result = mysqli_query($connection,$updateSQL) or die (mysqli_error($connection));
Expand Down
18 changes: 9 additions & 9 deletions includes/process/process_brewer_info.inc.php
Original file line number Diff line number Diff line change
Expand Up @@ -34,7 +34,7 @@
if (isset($_POST['brewerJudgeID'])) {
$brewerJudgeID = $purifier->purify($_POST['brewerJudgeID']);
$brewerJudgeID = strtoupper($brewerJudgeID);
$brewerJudgeID = filter_var($brewerJudgeID,FILTER_SANITIZE_STRING,FILTER_FLAG_ENCODE_HIGH|FILTER_FLAG_ENCODE_LOW);
$brewerJudgeID = filter_var($brewerJudgeID,FILTER_SANITIZE_STRING);
}

if (isset($_POST['brewerJudgeMead'])) $brewerJudgeMead = $_POST['brewerJudgeMead'];
Expand Down Expand Up @@ -64,13 +64,13 @@

if (isset($_POST['brewerBreweryName'])) {
$brewerBreweryName = standardize_name($purifier->purify($_POST['brewerBreweryName']));
$brewerBreweryName = filter_var($brewerBreweryName,FILTER_SANITIZE_STRING,FILTER_FLAG_ENCODE_HIGH|FILTER_FLAG_ENCODE_LOW);
$brewerBreweryName = filter_var($brewerBreweryName,FILTER_SANITIZE_STRING);
}

if (isset($_POST['brewerBreweryTTB'])) {
$brewerBreweryTTB = $purifier->purify($_POST['brewerBreweryTTB']);
$brewerBreweryTTB = strtoupper($brewerBreweryTTB);
$brewerBreweryTTB = filter_var($brewerBreweryTTB,FILTER_SANITIZE_STRING,FILTER_FLAG_ENCODE_HIGH|FILTER_FLAG_ENCODE_LOW);
$brewerBreweryTTB = filter_var($brewerBreweryTTB,FILTER_SANITIZE_STRING);
}

if (isset($_POST['brewerJudge'])) $brewerJudge = $_POST['brewerJudge'];
Expand All @@ -84,7 +84,7 @@
if (isset($_POST['brewerJudgeExp'])) $brewerJudgeExp = $_POST['brewerJudgeExp'];
if (isset($_POST['brewerJudgeNotes'])) {
$brewerJudgeNotes = $purifier->purify($_POST['brewerJudgeNotes']);
$brewerJudgeNotes = filter_var($brewerJudgeNotes,FILTER_SANITIZE_STRING,FILTER_FLAG_ENCODE_HIGH|FILTER_FLAG_ENCODE_LOW);
$brewerJudgeNotes = filter_var($brewerJudgeNotes,FILTER_SANITIZE_STRING);
}

/*
Expand Down Expand Up @@ -256,16 +256,16 @@
else {
$first_name = $fname;
$last_name = $lname;
$first_name = filter_var($first_name,FILTER_SANITIZE_STRING,FILTER_FLAG_ENCODE_HIGH|FILTER_FLAG_ENCODE_LOW);
$last_name = filter_var($last_name,FILTER_SANITIZE_STRING,FILTER_FLAG_ENCODE_HIGH|FILTER_FLAG_ENCODE_LOW);
$first_name = filter_var($first_name,FILTER_SANITIZE_STRING);
$last_name = filter_var($last_name,FILTER_SANITIZE_STRING);
}

$address = standardize_name($purifier->purify($_POST['brewerAddress']));
$address = filter_var($address,FILTER_SANITIZE_STRING,FILTER_FLAG_ENCODE_HIGH|FILTER_FLAG_ENCODE_LOW);
$address = filter_var($address,FILTER_SANITIZE_STRING);
$city = standardize_name($purifier->purify($_POST['brewerCity']));
$city = filter_var($city,FILTER_SANITIZE_STRING,FILTER_FLAG_ENCODE_HIGH|FILTER_FLAG_ENCODE_LOW);
$city = filter_var($city,FILTER_SANITIZE_STRING);
$state = $purifier->purify($_POST['brewerState']);
if (strlen($state) > 2) $state = standardize_name($state);
else $state = strtoupper($state);
$state = filter_var($state,FILTER_SANITIZE_STRING,FILTER_FLAG_ENCODE_HIGH|FILTER_FLAG_ENCODE_LOW);
$state = filter_var($state,FILTER_SANITIZE_STRING);
?>
44 changes: 22 additions & 22 deletions includes/process/process_brewing.inc.php
Original file line number Diff line number Diff line change
Expand Up @@ -75,7 +75,7 @@
$styleBreak = $_POST['brewStyle'];
$styleName = "";
$brewName = standardize_name($purifier->purify($_POST['brewName']));
$brewName = filter_var($brewName,FILTER_SANITIZE_STRING,FILTER_FLAG_ENCODE_HIGH|FILTER_FLAG_ENCODE_LOW);
$brewName = filter_var($brewName,FILTER_SANITIZE_STRING);
$brewInfo = "";
$brewInfoOptional = "";
$index = ""; // Defined with Style
Expand All @@ -93,7 +93,7 @@
// Comments
if ((isset($_POST['brewComments'])) && (!empty($_POST['brewComments']))) {
$brewComments = $purifier->purify($_POST['brewComments']);
$brewComments = filter_var($brewComments,FILTER_SANITIZE_STRING,FILTER_FLAG_ENCODE_HIGH|FILTER_FLAG_ENCODE_LOW);
$brewComments = filter_var($brewComments,FILTER_SANITIZE_STRING);
}

// Co Brewer
Expand All @@ -119,30 +119,30 @@

}

$brewCoBrewer = filter_var($brewCoBrewer,FILTER_SANITIZE_STRING,FILTER_FLAG_ENCODE_HIGH|FILTER_FLAG_ENCODE_LOW);
$brewCoBrewer = filter_var($brewCoBrewer,FILTER_SANITIZE_STRING);

}

// Possible Allergens
if ((isset($_POST['brewPossAllergens'])) && (!empty($_POST['brewPossAllergens']))) {
$brewPossAllergens = $purifier->purify($_POST['brewPossAllergens']);
$brewPossAllergens = filter_var($brewPossAllergens,FILTER_SANITIZE_STRING,FILTER_FLAG_ENCODE_HIGH|FILTER_FLAG_ENCODE_LOW);
$brewPossAllergens = filter_var($brewPossAllergens,FILTER_SANITIZE_STRING);
}

// Admin and Staff Notes
if ((isset($_POST['brewAdminNotes'])) && (!empty($_POST['brewAdminNotes']))) {
$brewAdminNotes = $purifier->purify($_POST['brewAdminNotes']);
$brewAdminNotes = filter_var($brewAdminNotes,FILTER_SANITIZE_STRING,FILTER_FLAG_ENCODE_HIGH|FILTER_FLAG_ENCODE_LOW);
$brewAdminNotes = filter_var($brewAdminNotes,FILTER_SANITIZE_STRING);
}

if ((isset($_POST['brewStaffNotes'])) && (!empty($_POST['brewStaffNotes']))) {
$brewStaffNotes = $purifier->purify($_POST['brewStaffNotes']);
$brewStaffNotes = filter_var($brewStaffNotes,FILTER_SANITIZE_STRING,FILTER_FLAG_ENCODE_HIGH|FILTER_FLAG_ENCODE_LOW);
$brewStaffNotes = filter_var($brewStaffNotes,FILTER_SANITIZE_STRING);
}

if ((isset($_POST['brewBoxNum'])) && (!empty($_POST['brewBoxNum']))) {
$brewBoxNum = $purifier->purify($_POST['brewBoxNum']);
$brewBoxNum = filter_var($brewBoxNum,FILTER_SANITIZE_STRING,FILTER_FLAG_ENCODE_HIGH|FILTER_FLAG_ENCODE_LOW);
$brewBoxNum = filter_var($brewBoxNum,FILTER_SANITIZE_STRING);
}

if (isset($_POST['brewReceived'])) $brewReceived = $_POST['brewReceived'];
Expand Down Expand Up @@ -181,34 +181,34 @@
// Checked against requirements later
if ((!empty($_POST['brewInfo'])) && (in_array($index, $all_special_ing_styles))) {
$brewInfo = $purifier->purify($_POST['brewInfo']);
$brewInfo = filter_var($brewInfo,FILTER_SANITIZE_STRING,FILTER_FLAG_ENCODE_HIGH|FILTER_FLAG_ENCODE_LOW);
$brewInfo = filter_var($brewInfo,FILTER_SANITIZE_STRING);
}

// Specialized/Optional info
if ((!empty($_POST['brewInfoOptional'])) && (in_array($index, $optional_info_styles))) {
$brewInfoOptional = $purifier->purify($_POST['brewInfoOptional']);
$brewInfoOptional = filter_var($brewInfoOptional,FILTER_SANITIZE_STRING,FILTER_FLAG_ENCODE_HIGH|FILTER_FLAG_ENCODE_LOW);
$brewInfoOptional = filter_var($brewInfoOptional,FILTER_SANITIZE_STRING);
}
// For BJCP 2015, process addtional info
if ($_SESSION['prefsStyleSet'] == "BJCP2015") {

// IPA strength for 21B styles
if (strlen(strstr($index,"21-B")) > 0) {
if ($index == "21-B") $brewInfo .= "^".filter_var($_POST['strengthIPA'],FILTER_SANITIZE_STRING,FILTER_FLAG_ENCODE_HIGH|FILTER_FLAG_ENCODE_LOW);
else $brewInfo .= filter_var($_POST['strengthIPA'],FILTER_SANITIZE_STRING,FILTER_FLAG_ENCODE_HIGH|FILTER_FLAG_ENCODE_LOW);
if ($index == "21-B") $brewInfo .= "^".filter_var($_POST['strengthIPA'],FILTER_SANITIZE_STRING);
else $brewInfo .= filter_var($_POST['strengthIPA'],FILTER_SANITIZE_STRING);
}

// Pale or Dark Variant
if (($index == "09-A") || ($index == "10-C") || ($index == "07-C")) $brewInfo = filter_var($_POST['darkLightColor'],FILTER_SANITIZE_STRING,FILTER_FLAG_ENCODE_HIGH|FILTER_FLAG_ENCODE_LOW);
if (($index == "09-A") || ($index == "10-C") || ($index == "07-C")) $brewInfo = filter_var($_POST['darkLightColor'],FILTER_SANITIZE_STRING);

// Fruit Lambic carb/sweetness
if ($index == "23-F") $brewInfo .= "^".filter_var($_POST['sweetnessLambic'],FILTER_SANITIZE_STRING,FILTER_FLAG_ENCODE_HIGH|FILTER_FLAG_ENCODE_LOW)."^".filter_var($_POST['carbLambic'],FILTER_SANITIZE_STRING,FILTER_FLAG_ENCODE_HIGH|FILTER_FLAG_ENCODE_LOW);
if ($index == "23-F") $brewInfo .= "^".filter_var($_POST['sweetnessLambic'],FILTER_SANITIZE_STRING,FILTER_FLAG_ENCODE_HIGH|FILTER_FLAG_ENCODE_LOW)."^".filter_var($_POST['carbLambic'],FILTER_SANITIZE_STRING);

// Biere de Garde color
if ($index == "24-C") $brewInfo = filter_var($_POST['BDGColor'],FILTER_SANITIZE_STRING,FILTER_FLAG_ENCODE_HIGH|FILTER_FLAG_ENCODE_LOW);
if ($index == "24-C") $brewInfo = filter_var($_POST['BDGColor'],FILTER_SANITIZE_STRING);

// Saison strength/color
if ($index == "25-B") $brewInfo = filter_var($_POST['strengthSaison'],FILTER_SANITIZE_STRING,FILTER_FLAG_ENCODE_HIGH|FILTER_FLAG_ENCODE_LOW)."^".filter_var($_POST['darkLightColor'],FILTER_SANITIZE_STRING,FILTER_FLAG_ENCODE_HIGH|FILTER_FLAG_ENCODE_LOW);
if ($index == "25-B") $brewInfo = filter_var($_POST['strengthSaison'],FILTER_SANITIZE_STRING,FILTER_FLAG_ENCODE_HIGH|FILTER_FLAG_ENCODE_LOW)."^".filter_var($_POST['darkLightColor'],FILTER_SANITIZE_STRING);

}

Expand Down Expand Up @@ -326,10 +326,10 @@

}

$brewInfo = filter_var($brewInfo,FILTER_SANITIZE_STRING,FILTER_FLAG_ENCODE_HIGH|FILTER_FLAG_ENCODE_LOW);
$brewInfoOptional = filter_var($brewInfoOptional,FILTER_SANITIZE_STRING,FILTER_FLAG_ENCODE_HIGH|FILTER_FLAG_ENCODE_LOW);
$brewStaffNotes = filter_var($brewStaffNotes,FILTER_SANITIZE_STRING,FILTER_FLAG_ENCODE_HIGH|FILTER_FLAG_ENCODE_LOW);
$brewAdminNotes = filter_var($brewAdminNotes,FILTER_SANITIZE_STRING,FILTER_FLAG_ENCODE_HIGH|FILTER_FLAG_ENCODE_LOW);
$brewInfo = filter_var($brewInfo,FILTER_SANITIZE_STRING);
$brewInfoOptional = filter_var($brewInfoOptional,FILTER_SANITIZE_STRING);
$brewStaffNotes = filter_var($brewStaffNotes,FILTER_SANITIZE_STRING);
$brewAdminNotes = filter_var($brewAdminNotes,FILTER_SANITIZE_STRING);

}

Expand Down Expand Up @@ -1020,17 +1020,17 @@

if (isset($_POST['brewBoxNum'.$id])) {
$brewBoxNum = $purifier->purify($_POST['brewBoxNum'.$id]);
$brewBoxNum = filter_var($brewBoxNum,FILTER_SANITIZE_STRING,FILTER_FLAG_ENCODE_HIGH|FILTER_FLAG_ENCODE_LOW);
$brewBoxNum = filter_var($brewBoxNum,FILTER_SANITIZE_STRING);
}

if (isset($_POST['brewAdminNotes'.$id])) {
$brewAdminNotes = $purifier->purify($_POST['brewAdminNotes'.$id]);
$brewAdminNotes = filter_var($brewAdminNotes,FILTER_SANITIZE_STRING,FILTER_FLAG_ENCODE_HIGH|FILTER_FLAG_ENCODE_LOW);
$brewAdminNotes = filter_var($brewAdminNotes,FILTER_SANITIZE_STRING);
}

if (isset($_POST['brewStaffNotes'.$id])) {
$brewStaffNotes = $purifier->purify($_POST['brewStaffNotes'.$id]);
$brewStaffNotes = filter_var($brewStaffNotes,FILTER_SANITIZE_STRING,FILTER_FLAG_ENCODE_HIGH|FILTER_FLAG_ENCODE_LOW);
$brewStaffNotes = filter_var($brewStaffNotes,FILTER_SANITIZE_STRING);
}

if ((isset($_POST['brewPaid'.$id])) && ($_POST['brewPaid'.$id] == 1)) $brewPaid = 1;
Expand Down
4 changes: 2 additions & 2 deletions includes/process/process_judging_locations.inc.php
Original file line number Diff line number Diff line change
Expand Up @@ -12,9 +12,9 @@

$judgingDate = strtotime(sterilize($_POST['judgingDate']));
$judgingLocName = $purifier->purify($_POST['judgingLocName']);
$judgingLocName = filter_var($judgingLocName,FILTER_SANITIZE_STRING,FILTER_FLAG_ENCODE_HIGH|FILTER_FLAG_ENCODE_LOW);
$judgingLocName = filter_var($judgingLocName,FILTER_SANITIZE_STRING);
$judgingLocation = $purifier->purify($_POST['judgingLocation']);
$judgingLocation = filter_var($judgingLocation,FILTER_SANITIZE_STRING,FILTER_FLAG_ENCODE_HIGH|FILTER_FLAG_ENCODE_LOW);
$judgingLocation = filter_var($judgingLocation,FILTER_SANITIZE_STRING);

$judgingDateEnd = "";
if (!empty($_POST['judgingDateEnd'])) $judgingDateEnd = strtotime(sterilize($_POST['judgingDateEnd']));
Expand Down
2 changes: 1 addition & 1 deletion includes/process/process_judging_tables.inc.php
Original file line number Diff line number Diff line change
Expand Up @@ -19,7 +19,7 @@
else $table_styles = $_POST['tableStyles'];
if (isset($_POST['tableName'])) {
$tableName = $purifier->purify($_POST['tableName']);
$tableName = filter_var($tableName,FILTER_SANITIZE_STRING,FILTER_FLAG_ENCODE_HIGH|FILTER_FLAG_ENCODE_LOW);
$tableName = filter_var($tableName,FILTER_SANITIZE_STRING);
}
else $tableName = "";

Expand Down
4 changes: 2 additions & 2 deletions includes/process/process_special_best.inc.php
Original file line number Diff line number Diff line change
Expand Up @@ -12,13 +12,13 @@

if (isset($_POST['sbi_name']) {
$sbi_name = $purifier->purify($_POST['sbi_name']);
$sbi_name = filter_var($sbi_name,FILTER_SANITIZE_STRING,FILTER_FLAG_ENCODE_HIGH|FILTER_FLAG_ENCODE_LOW);
$sbi_name = filter_var($sbi_name,FILTER_SANITIZE_STRING);
}
else $sbi_name = "";

if (isset($_POST['sbi_description'])) {
$sbi_description = $purifier->purify($_POST['sbi_description']);
$sbi_description = filter_var($sbi_description,FILTER_SANITIZE_STRING,FILTER_FLAG_ENCODE_HIGH|FILTER_FLAG_ENCODE_LOW);
$sbi_description = filter_var($sbi_description,FILTER_SANITIZE_STRING);
}
else $sbi_description = "";

Expand Down
4 changes: 2 additions & 2 deletions includes/process/process_special_best_info.inc.php
Original file line number Diff line number Diff line change
Expand Up @@ -16,12 +16,12 @@

if (isset($_POST['sbi_name'])) {
$sbi_name = $purifier->purify($_POST['sbi_name']);
$sbi_name = filter_var($sbi_name,FILTER_SANITIZE_STRING,FILTER_FLAG_ENCODE_HIGH|FILTER_FLAG_ENCODE_LOW);
$sbi_name = filter_var($sbi_name,FILTER_SANITIZE_STRING);
}

if (isset($_POST['sbi_description'])) {
$sbi_description = $purifier->purify($_POST['sbi_description']);
$sbi_description = filter_var($sbi_description,FILTER_SANITIZE_STRING,FILTER_FLAG_ENCODE_HIGH|FILTER_FLAG_ENCODE_LOW);
$sbi_description = filter_var($sbi_description,FILTER_SANITIZE_STRING);
}

if ($action == "add") {
Expand Down
10 changes: 5 additions & 5 deletions includes/process/process_sponsors.inc.php
Original file line number Diff line number Diff line change
Expand Up @@ -14,7 +14,7 @@

foreach($_POST['id'] as $id) {
$sponsor_info = $purifier->purify($_POST['sponsorText'.$id]);
$sponsor_info = filter_var($sponsor_info,FILTER_SANITIZE_STRING,FILTER_FLAG_ENCODE_HIGH|FILTER_FLAG_ENCODE_LOW);
$sponsor_info = filter_var($sponsor_info,FILTER_SANITIZE_STRING);
if ($_POST['sponsorEnable'.$id] == 1) $enable = 1; else $enable = 0;
if (isset($_POST['sponsorImage'.$id])) $image = $purifier->purify($_POST['sponsorImage'.$id]); else $image = "";
$updateSQL = sprintf("UPDATE %s SET sponsorEnable='%s', sponsorLevel='%s', sponsorImage='%s', sponsorText='%s' WHERE id='%s'",$sponsors_db_table,$enable,$_POST['sponsorLevel'.$id],$image,$sponsor_info,$id);
Expand All @@ -32,9 +32,9 @@

$sponsorURL = check_http($purifier->purify($_POST['sponsorURL']));
$sponsor_name = capitalize($purifier->purify($_POST['sponsorName']));
$sponsor_name = filter_var($sponsor_name,FILTER_SANITIZE_STRING,FILTER_FLAG_ENCODE_HIGH|FILTER_FLAG_ENCODE_LOW);
$sponsor_name = filter_var($sponsor_name,FILTER_SANITIZE_STRING);
$sponsor_info = $purifier->purify($_POST['sponsorText']);
$sponsor_info = filter_var($sponsor_info,FILTER_SANITIZE_STRING,FILTER_FLAG_ENCODE_HIGH|FILTER_FLAG_ENCODE_LOW);
$sponsor_info = filter_var($sponsor_info,FILTER_SANITIZE_STRING);

$insertSQL = sprintf("INSERT INTO $sponsors_db_table (sponsorName, sponsorURL, sponsorImage, sponsorText, sponsorLocation, sponsorLevel, sponsorEnable) VALUES (%s, %s, %s, %s, %s, %s, %s)",
GetSQLValueString($sponsor_name, "text"),
Expand All @@ -60,9 +60,9 @@

$sponsorURL = check_http($purifier->purify($_POST['sponsorURL']));
$sponsor_name = capitalize($purifier->purify($_POST['sponsorName']));
$sponsor_name = filter_var($sponsor_name,FILTER_SANITIZE_STRING,FILTER_FLAG_ENCODE_HIGH|FILTER_FLAG_ENCODE_LOW);
$sponsor_name = filter_var($sponsor_name,FILTER_SANITIZE_STRING);
$sponsor_info = $purifier->purify($_POST['sponsorText']);
$sponsor_info = filter_var($sponsor_info,FILTER_SANITIZE_STRING,FILTER_FLAG_ENCODE_HIGH|FILTER_FLAG_ENCODE_LOW);
$sponsor_info = filter_var($sponsor_info,FILTER_SANITIZE_STRING);

$updateSQL = sprintf("UPDATE $sponsors_db_table SET sponsorName=%s, sponsorURL=%s, sponsorImage=%s, sponsorText=%s, sponsorLocation=%s , sponsorLevel=%s, sponsorEnable=%s WHERE id=%s",
GetSQLValueString($sponsor_name, "text"),
Expand Down
2 changes: 1 addition & 1 deletion includes/process/process_style_types.inc.php
Original file line number Diff line number Diff line change
Expand Up @@ -13,7 +13,7 @@
if (isset($_POST['styleTypeName'])) {
$styleTypeName = $purifier->purify($_POST['styleTypeName']);
$styleTypeName = capitalize($styleTypeName);
$styleTypeName = filter_var($styleTypeName,FILTER_SANITIZE_STRING,FILTER_FLAG_ENCODE_HIGH|FILTER_FLAG_ENCODE_LOW);
$styleTypeName = filter_var($styleTypeName,FILTER_SANITIZE_STRING);
}

if ($action == "add") {
Expand Down
2 changes: 1 addition & 1 deletion includes/process/process_styles.inc.php
Original file line number Diff line number Diff line change
Expand Up @@ -20,7 +20,7 @@
if (isset($_POST['brewStyleEntry'])) {
$brewStyleEntry = trim($_POST['brewStyleEntry']);
$brewStyleEntry = $purifier->purify($brewStyleEntry);
$brewStyleEntry = filter_var($brewStyleEntry,FILTER_SANITIZE_STRING,FILTER_FLAG_ENCODE_HIGH|FILTER_FLAG_ENCODE_LOW);
$brewStyleEntry = filter_var($brewStyleEntry,FILTER_SANITIZE_STRING);
}

if (isset($_POST['brewStyleInfo'])) {
Expand Down
20 changes: 10 additions & 10 deletions update/off_schedule_update.php
Original file line number Diff line number Diff line change
Expand Up @@ -607,22 +607,22 @@
else {
$first_name = $fname;
$last_name = $lname;
$first_name = filter_var($first_name,FILTER_SANITIZE_STRING,FILTER_FLAG_ENCODE_HIGH|FILTER_FLAG_ENCODE_LOW);
$last_name = filter_var($last_name,FILTER_SANITIZE_STRING,FILTER_FLAG_ENCODE_HIGH|FILTER_FLAG_ENCODE_LOW);
$first_name = filter_var($first_name,FILTER_SANITIZE_STRING);
$last_name = filter_var($last_name,FILTER_SANITIZE_STRING);
}

$address = standardize_name($purifier->purify($row_names['brewerAddress']));
$address = filter_var($address,FILTER_SANITIZE_STRING,FILTER_FLAG_ENCODE_HIGH|FILTER_FLAG_ENCODE_LOW);
$address = filter_var($address,FILTER_SANITIZE_STRING);
$city = standardize_name($purifier->purify($row_names['brewerCity']));
$city = filter_var($city,FILTER_SANITIZE_STRING,FILTER_FLAG_ENCODE_HIGH|FILTER_FLAG_ENCODE_LOW);
$city = filter_var($city,FILTER_SANITIZE_STRING);
$state = $purifier->purify($row_names['brewerState']);
if (strlen($state) > 2) $state = standardize_name($state);
else $state = strtoupper($state);
$state = filter_var($state,FILTER_SANITIZE_STRING,FILTER_FLAG_ENCODE_HIGH|FILTER_FLAG_ENCODE_LOW);
$state = filter_var($state,FILTER_SANITIZE_STRING);

if (!empty($row_names['brewerJudgeID'])) {
$brewerJudgeID = sterilize($row_names['brewerJudgeID']);
$brewerJudgeID = filter_var($brewerJudgeID,FILTER_SANITIZE_STRING,FILTER_FLAG_ENCODE_HIGH|FILTER_FLAG_ENCODE_LOW);
$brewerJudgeID = filter_var($brewerJudgeID,FILTER_SANITIZE_STRING);
$brewerJudgeID = strtoupper($brewerJudgeID);
}
else $brewerJudgeID = "";
Expand All @@ -634,7 +634,7 @@

if (!empty($row_names['brewerJudgeNotes'])) {
$brewerJudgeNotes = $purifier->purify($row_names['brewerJudgeNotes']);
$brewerJudgeNotes = filter_var($brewerJudgeNotes,FILTER_SANITIZE_STRING,FILTER_FLAG_ENCODE_HIGH|FILTER_FLAG_ENCODE_LOW);
$brewerJudgeNotes = filter_var($brewerJudgeNotes,FILTER_SANITIZE_STRING);
}
else $brewerJudgeNotes = "";

Expand Down Expand Up @@ -703,20 +703,20 @@

}

$brewCoBrewer = filter_var($brewCoBrewer,FILTER_SANITIZE_STRING,FILTER_FLAG_ENCODE_HIGH|FILTER_FLAG_ENCODE_LOW);
$brewCoBrewer = filter_var($brewCoBrewer,FILTER_SANITIZE_STRING);

}

else $brewCoBrewer = "";

if (isset($row_entry_names['brewInfo'])) {
$brewInfo = $purifier->purify($row_entry_names['brewInfo']);
$brewInfo = filter_var($brewInfo,FILTER_SANITIZE_STRING,FILTER_FLAG_ENCODE_HIGH|FILTER_FLAG_ENCODE_LOW);
$brewInfo = filter_var($brewInfo,FILTER_SANITIZE_STRING);
}
else $brewInfo = "";

$brewName = standardize_name($purifier->purify($row_entry_names['brewName']));
$brewName = filter_var($brewName,FILTER_SANITIZE_STRING,FILTER_FLAG_ENCODE_HIGH|FILTER_FLAG_ENCODE_LOW);
$brewName = filter_var($brewName,FILTER_SANITIZE_STRING);

$updateSQL = sprintf("UPDATE %s SET
brewJudgingNumber=%s,
Expand Down

0 comments on commit 69daa47

Please sign in to comment.