MDL-26196 fix param validation
authorPetr Skoda <commits@skodak.org>
Sun, 30 Jan 2011 18:27:04 +0000 (19:27 +0100)
committerPetr Skoda <commits@skodak.org>
Sun, 30 Jan 2011 18:27:04 +0000 (19:27 +0100)
tag/coursetags_more.php

index d5e77f0..b1075a1 100644 (file)
@@ -9,8 +9,8 @@ require_once('../config.php');
 require_once($CFG->dirroot.'/tag/coursetagslib.php');
 require_once($CFG->dirroot.'/tag/lib.php');
 
-$sort = optional_param('sort', 'alpha', PARAM_TEXT); //alpha, date or popularity
-$show = optional_param('show', 'all', PARAM_TEXT); //all, my, official, community or course
+$sort = optional_param('sort', 'alpha', PARAM_ALPHA); //alpha, date or popularity
+$show = optional_param('show', 'all', PARAM_ALPHA); //all, my, official, community or course
 $courseid = optional_param('courseid', 0, PARAM_INT);
 
 $url = new moodle_url('/tag/coursetags_more.php');