diff --git a/accred_form.php b/accred_form.php index 8b820a71..aa898298 100644 --- a/accred_form.php +++ b/accred_form.php @@ -119,12 +119,13 @@ $d = $mysqli->real_escape_string(serialize($_POST)); if(!$aid) { // Make sure we set the demande_our value to current user if blank // This would happen upon submission of a new record by non-admin person - if($d['demande_pour']=='') { - $d['demande_pour'] = $username; + if($_POST['demande_pour']=='') { + $m = $_POST; + $m['demande_pour'] = $username; + $d = $mysqli->real_escape_string(serialize($m)); } $query = "INSERT INTO submissions (uid, status, name, created, formdata,modified) values('$userid',$status,'$username',null,'".$d."',NOW())"; syslog(LOG_INFO, "Create entry by uid: $userid / $uname from: {$_SERVER['REMOTE_ADDR']} ({$_SERVER['HTTP_USER_AGENT']})"); - } else { $query = "UPDATE submissions set modifieduid=$userid,formdata='".$d."'";