dont escape the query that is send to search escape on the way out

v1.18.x
barisusakli 10 years ago
parent 244c75f809
commit 6e66b32fe1

@ -17,7 +17,6 @@ searchController.search = function(req, res, next) {
return next();
}
req.params.term = validator.escape(req.params.term);
var page = Math.max(1, parseInt(req.query.page, 10)) || 1;
if (req.query.categories && !Array.isArray(req.query.categories)) {
req.query.categories = [req.query.categories];

@ -1,6 +1,7 @@
'use strict';
var async = require('async'),
validator = require('validator'),
db = require('./database'),
posts = require('./posts'),
@ -21,7 +22,7 @@ search.search = function(data, callback) {
return callback(err);
}
result.search_query = query;
result.search_query = validator.escape(query);
if (searchIn === 'titles' || searchIn === 'titlesposts') {
searchIn = 'posts';
}

Loading…
Cancel
Save