From 47d0cdca049416b9a21b6c1a837187fad8539038 Mon Sep 17 00:00:00 2001
From: Janne Koschinski <janne@kuschku.de>
Date: Mon, 17 Oct 2016 02:28:36 +0200
Subject: [PATCH] Escape normal messages, too

---
 backend/Database.php | 8 ++++----
 1 file changed, 4 insertions(+), 4 deletions(-)

diff --git a/backend/Database.php b/backend/Database.php
index f30d30b..aed4c60 100644
--- a/backend/Database.php
+++ b/backend/Database.php
@@ -40,7 +40,7 @@ class Backend {
                    tmp.messageid,
                    sender.sender,
                    tmp.time,
-                   replace(replace(tmp.message, '<', '&lt;'), '>', '&gt;'),
+                   replace(replace(tmp.message, '<', '&lt;'), '>', '&gt;') AS message,
                    ts_headline(replace(replace(tmp.message, '<', '&lt;'), '>', '&gt;'), query) AS preview
             FROM
               (SELECT backlog.messageid,
@@ -67,7 +67,7 @@ class Backend {
             SELECT backlog.messageid,
                    sender.sender,
                    backlog.time,
-                   replace(replace(backlog.message, '<', '&lt;'), '>', '&gt;'),
+                   replace(replace(backlog.message, '<', '&lt;'), '>', '&gt;') AS message,
                    ts_headline(replace(replace(backlog.message, '<', '&lt;'), '>', '&gt;'), query) AS preview
             FROM backlog
             JOIN sender ON backlog.senderid = sender.senderid
@@ -87,7 +87,7 @@ class Backend {
                    sender.sender,
                    backlog.time,
                    network.networkname,
-                   replace(replace(backlog.message, '<', '&lt;'), '>', '&gt;')
+                   replace(replace(backlog.message, '<', '&lt;'), '>', '&gt;') AS message
             FROM backlog
             JOIN sender ON backlog.senderid = sender.senderid
             JOIN buffer ON backlog.bufferid = buffer.bufferid
@@ -105,7 +105,7 @@ class Backend {
                    sender.sender,
                    backlog.time,
                    network.networkname,
-                   replace(replace(backlog.message, '<', '&lt;'), '>', '&gt;')
+                   replace(replace(backlog.message, '<', '&lt;'), '>', '&gt;') AS message
             FROM backlog
             JOIN sender ON backlog.senderid = sender.senderid
             JOIN buffer ON backlog.bufferid = buffer.bufferid
-- 
GitLab