- Fix all SQL injection vulnerabilities across Service_model, User_model, Module_model, Log_model, and Admin controller using parameterized queries - Add htmlspecialchars() to all user-controlled output in admin views (bookings, services, workers, service categories, login form) - Fix XSS in AJAX worker response and manage-booking-cancelled view - Add file extension whitelist (jpg, jpeg, png, gif, webp) to all uploads - Remove webshell (pentest2.php) from assets/img/profiles/ - Stop logging plaintext passwords on failed login attempts - Migrate database.php hostname from localhost to AWS RDS endpoint - Fix dropdown styling (white-on-white) in worker calendar view Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
24 lines
620 B
PHP
Executable File
24 lines
620 B
PHP
Executable File
<?php
|
|
class Log_model extends CI_Model {
|
|
|
|
function __construct(){
|
|
parent::__construct();
|
|
}
|
|
|
|
public function addLog($eventType, $eventContent, $username=""){
|
|
$this->load->database();
|
|
$query = $this->db->query("INSERT INTO system_log(event_type, event_content, username) VALUES(?, ?, ?)", array($eventType, $eventContent, $username));
|
|
}
|
|
|
|
public function getAllLoginfo(){
|
|
$this->load->database();
|
|
$query = $this->db->query('SELECT * FROM system_log ORDER BY event_datetime DESC;');
|
|
return $query->result();
|
|
}
|
|
|
|
|
|
|
|
|
|
}
|
|
|
|
?>
|