Skip to content
Snippets Groups Projects
Commit 80d1037e authored by Bart Visscher's avatar Bart Visscher
Browse files

Group name does't need to be sanitized before storing it in the database

It should only be sanitized before display
parent 71e8755d
No related branches found
No related tags found
No related merge requests found
......@@ -5,7 +5,7 @@ OCP\JSON::callCheck();
$success = true;
$username = $_POST["username"];
$group = OC_Util::sanitizeHTML($_POST["group"]);
$group = $_POST["group"];
if(!OC_Group::inGroup(OC_User::getUser(), 'admin') && (!OC_SubAdmin::isUserAccessible(OC_User::getUser(), $username) || !OC_SubAdmin::isGroupAccessible(OC_User::getUser(), $group))) {
$l = OC_L10N::get('core');
......
......@@ -4,7 +4,7 @@ OC_JSON::checkAdminUser();
OCP\JSON::callCheck();
$username = $_POST["username"];
$group = OC_Util::sanitizeHTML($_POST["group"]);
$group = $_POST["group"];
// Toggle group
if(OC_SubAdmin::isSubAdminofGroup($username, $group)) {
......
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Please register or to comment