Commit 6336c562 authored by Andrew Nicols's avatar Andrew Nicols

MDL-53696 forum: Check discussion in forum

parent aca2ff0a
......@@ -53,7 +53,9 @@ if (!is_null($sesskey)) {
}
if (!is_null($discussionid)) {
$url->param('d', $discussionid);
$discussion = $DB->get_record('forum_discussions', array('id' => $discussionid), '*', MUST_EXIST);
if (!$discussion = $DB->get_record('forum_discussions', array('id' => $discussionid, 'forum' => $id))) {
print_error('invaliddiscussionid', 'forum');
}
}
$PAGE->set_url($url);
......
......@@ -32,7 +32,7 @@ $includetext = optional_param('includetext', false, PARAM_BOOL);
$forum = $DB->get_record('forum', array('id' => $forumid), '*', MUST_EXIST);
$course = $DB->get_record('course', array('id' => $forum->course), '*', MUST_EXIST);
$discussion = $DB->get_record('forum_discussions', array('id' => $discussionid), '*', MUST_EXIST);
$discussion = $DB->get_record('forum_discussions', array('id' => $discussionid, 'forum' => $forumid), '*', MUST_EXIST);
$cm = get_coursemodule_from_instance('forum', $forum->id, $course->id, false, MUST_EXIST);
$context = context_module::instance($cm->id);
......
Markdown is supported
0%
or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment