fix prepared statement combination

This commit is contained in:
Daniel Seifert 2021-04-28 22:41:03 +02:00
parent 564ddd891d
commit 3d52203d94
Signed by: DanielS
GPG Key ID: 6A513E13AEE66170
1 changed files with 2 additions and 1 deletions

View File

@ -58,10 +58,11 @@ class d3_dev_oxorder extends d3_dev_oxorder_parent
{
$orderNr = (int) Registry::getRequest()->getRequestEscapedParameter('d3ordernr');
$sWhere = 1;
$parameters = [];
if ($orderNr) {
$sWhere = ' oxordernr = ? ';
$parameters[] = $orderNr;
}
$parameters = [$orderNr];
$sSelect = "SELECT oxid FROM ".oxNew(Order::class)->getViewName()." WHERE ".
"oxuserid != '' AND ".