diff --git a/libraries/bookmark.lib.php b/libraries/bookmark.lib.php index 69753cd22..4373fae1f 100644 --- a/libraries/bookmark.lib.php +++ b/libraries/bookmark.lib.php @@ -87,12 +87,13 @@ function PMA_listBookmarks($db, $cfgBookmark) * @param mixed the id of the bookmark to get * @param string which field to look up the $id * @param boolean TRUE: get all bookmarks regardless of the owning user + * @param boolean whether to ignore bookmarks with no user * * @return string the sql query * * @access public */ -function PMA_queryBookmarks($db, $cfgBookmark, $id, $id_field = 'id', $action_bookmark_all = FALSE) +function PMA_queryBookmarks($db, $cfgBookmark, $id, $id_field = 'id', $action_bookmark_all = FALSE, $exact_user_match = FALSE) { global $controllink; @@ -100,11 +101,19 @@ function PMA_queryBookmarks($db, $cfgBookmark, $id, $id_field = 'id', $action_bo return ''; } - $query = 'SELECT query FROM ' . PMA_backquote($cfgBookmark['db']) . '.' . PMA_backquote($cfgBookmark['table']) - . ' WHERE dbase = \'' . PMA_sqlAddslashes($db) . '\'' - . ($action_bookmark_all? '' : ' AND (user = \'' . PMA_sqlAddslashes($cfgBookmark['user']) . '\'' - . ' OR user = \'\')') - . ' AND ' . PMA_backquote($id_field) . ' = ' . $id; + $query = 'SELECT query FROM ' . PMA_backquote($cfgBookmark['db']) . '.' . PMA_backquote($cfgBookmark['table']) + . ' WHERE dbase = \'' . PMA_sqlAddslashes($db) . '\''; + + if (!$action_bookmark_all) { + $query .= ' AND (user = \'' . PMA_sqlAddslashes($cfgBookmark['user']) . '\''; + if (!$exact_user_match) { + $query .= ' OR user = \'\''; + } + $query .= ')'; + } + + $query .= ' AND ' . PMA_backquote($id_field) . ' = ' . $id; + $result = PMA_DBI_try_query($query, $controllink); if (!$result) { return FALSE; diff --git a/sql.php b/sql.php index 2a744c57c..0040c0c11 100644 --- a/sql.php +++ b/sql.php @@ -54,7 +54,7 @@ if (empty($sql_query) && strlen($table) && strlen($db)) { require_once './libraries/bookmark.lib.php'; $book_sql_query = PMA_queryBookmarks($db, $GLOBALS['cfg']['Bookmark'], '\'' . PMA_sqlAddslashes($table) . '\'', - 'label'); + 'label', FALSE, TRUE); if (! empty($book_sql_query)) { $sql_query = $book_sql_query;