From e468e5a5896a7f3f3df2ca45115add020d0d44b9 Mon Sep 17 00:00:00 2001 From: Andrew Dolgov Date: Wed, 24 Feb 2021 10:09:08 +0300 Subject: [PATCH] cats_of: enforce owner_uid --- classes/feeds.php | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/classes/feeds.php b/classes/feeds.php index d32c19d5d..87fdc0bfe 100755 --- a/classes/feeds.php +++ b/classes/feeds.php @@ -1798,8 +1798,8 @@ class Feeds extends Handler_Protected { $sth = $pdo->prepare("SELECT DISTINCT cat_id, fc.parent_cat FROM ttrss_feeds f LEFT JOIN ttrss_feed_categories fc ON (fc.id = f.cat_id) - WHERE f.id IN ($feeds_qmarks)"); - $sth->execute($feeds); + WHERE f.owner_uid = ? AND f.id IN ($feeds_qmarks)"); + $sth->execute(array_merge([$owner_uid], $feeds)); $rv = [];