Remove extraneous code. Note: this is another example of unchecked input, yet unfixed.

Signed-off-by: Joshua Ferraro <jmf@liblime.com>
This commit is contained in:
Joe Atzberger 2008-04-21 16:22:42 -05:00 committed by Joshua Ferraro
parent fa8005ccbc
commit a98c622ab8

View file

@ -31,7 +31,7 @@ my $query = new CGI;
my $biblionumber = $query->param('biblionumber'); my $biblionumber = $query->param('biblionumber');
my $type = $query->param('type'); my $type = $query->param('type');
my $review = $query->param('review'); my $review = $query->param('review');
my $reviewid = $query->param('reviewid'); my $reviewid = $query->param('reviewid');
my ( $template, $borrowernumber, $cookie ) = get_template_and_user( my ( $template, $borrowernumber, $cookie ) = get_template_and_user(
{ {
template_name => "opac-review.tmpl", template_name => "opac-review.tmpl",
@ -47,38 +47,18 @@ my $savedreview = getreview( $biblionumber, $borrowernumber );
if ( $type eq 'save' ) { if ( $type eq 'save' ) {
savereview( $biblionumber, $borrowernumber, $review ); savereview( $biblionumber, $borrowernumber, $review );
} }
if ( $type eq 'update' ) { elsif ( $type eq 'update' ) {
updatereview( $biblionumber, $borrowernumber, $review ); updatereview( $biblionumber, $borrowernumber, $review );
} }
if ($savedreview) { $type = ($savedreview) ? "update" : "save";
$type = "update";
}
else {
$type = "save";
}
my $reviewdata = $savedreview->{'review'};
$template->param( $template->param(
'biblionumber' => $biblionumber, 'biblionumber' => $biblionumber,
'borrowernumber' => $borrowernumber, 'borrowernumber' => $borrowernumber,
'type' => $type, 'type' => $type,
'review' => $reviewdata, 'review' => $savedreview->{'review'},
'reviewid' => $reviewid, 'reviewid' => $reviewid,
'title' => $biblio->{'title'}, 'title' => $biblio->{'title'},
); );
# get the record
my $order = $query->param('order');
my $order2 = $order;
if ( $order2 eq '' ) {
$order2 = "date_due desc";
}
my $limit = $query->param('limit');
if ( $limit eq 'full' ) {
$limit = 0;
}
else {
$limit = 50;
}
output_html_with_http_headers $query, $cookie, $template->output; output_html_with_http_headers $query, $cookie, $template->output;