mirror of
https://github.com/wavelog/wavelog.git
synced 2026-03-22 10:24:14 +00:00
fix db search for json values
This commit is contained in:
@@ -753,10 +753,14 @@ class User_Model extends CI_Model {
|
|||||||
return 0;
|
return 0;
|
||||||
}
|
}
|
||||||
|
|
||||||
// FUNCTION: retrieve a user by their SSO composite key (md5(iss).sub)
|
// FUNCTION: retrieve a user by their SSO composite key {iss, sub} stored as JSON
|
||||||
function get_by_external_account(string $key) {
|
function get_by_external_account(string $key) {
|
||||||
$this->db->where('external_account', $key);
|
$table = $this->config->item('auth_table');
|
||||||
return $this->db->get($this->config->item('auth_table'));
|
$decoded = json_decode($key, true);
|
||||||
|
return $this->db->query(
|
||||||
|
"SELECT * FROM `$table` WHERE JSON_VALUE(external_account, '$.iss') = ? AND JSON_VALUE(external_account, '$.sub') = ?",
|
||||||
|
[$decoded['iss'], $decoded['sub']]
|
||||||
|
);
|
||||||
}
|
}
|
||||||
|
|
||||||
// FUNCTION: update specific user fields from SSO claims (bypass privilege check, used during login flow)
|
// FUNCTION: update specific user fields from SSO claims (bypass privilege check, used during login flow)
|
||||||
|
|||||||
Reference in New Issue
Block a user