// htmlspecialchars on the sql queries in the profiling mode

This commit is contained in:
Damien Metzger
2013-02-13 15:39:22 +01:00
parent 7fc33eb01c
commit cc1ff8ef0f
+1 -1
View File
@@ -387,7 +387,7 @@ abstract class Controller extends ControllerCore
uasort($queries, 'prestashop_querytime_sort');
foreach ($queries as $data)
{
echo $hr.'<b '.$this->getTimeColor($data['time'] * 1000).'>'.round($data['time'] * 1000, 3).' ms</b> '.$data['query'].'<br />in '.$data['file'].':'.$data['line'].'<br />';
echo $hr.'<b '.$this->getTimeColor($data['time'] * 1000).'>'.round($data['time'] * 1000, 3).' ms</b> '.htmlspecialchars($data['query'], ENT_NOQUOTES, 'utf-8', false).'<br />in '.$data['file'].':'.$data['line'].'<br />';
if (preg_match('/^\s*select\s+/i', $data['query']))
{
$explain = Db::getInstance()->executeS('explain '.$data['query']);