diff -r 06dd071a429d -r 4082c41f45e9 www/includes/db_setup.php --- a/www/includes/db_setup.php Sun Feb 24 21:22:25 2019 +0100 +++ b/www/includes/db_setup.php Sun Feb 24 22:29:00 2019 +0100 @@ -27,13 +27,14 @@ $sql .= "', factor_fwh='" . $_POST['factor_fwh']; $sql .= "', factor_pellet='" . $_POST['factor_pellet']; $sql .= "', factor_plug='" . $_POST['factor_plug']; - $sql .= "', color_method='" . mysqli_real_escape_string($connect, $_POST['color_method']); - $sql .= "', ibu_method='" . mysqli_real_escape_string($connect, $_POST['ibu_method']); + $sql .= "', factor_wethop='" . $_POST['factor_wethop']; + $sql .= "', color_method='" . $_POST['color_method']; + $sql .= "', ibu_method='" . $_POST['ibu_method']; $sql .= "', brix_correction='" . $_POST['brix_correction']; $sql .= "', grain_absorbtion='" . $_POST['grain_absorbtion']; $sql .= "', default_water='" . $default_water; $sql .= "' WHERE record='1';"; -// syslog(LOG_NOTICE, $sql); + //syslog(LOG_NOTICE, $sql); $result = mysqli_query($connect, $sql); if (! $result) { syslog(LOG_NOTICE, "db_profile_setup: ".$sql." result: ".mysqli_error($connect)); @@ -56,9 +57,10 @@ $data .= ',"factor_fwh":' . $row['factor_fwh']; $data .= ',"factor_pellet":' . $row['factor_pellet']; $data .= ',"factor_plug":' . $row['factor_plug']; - $data .= ',"ibu_method":"' . str_replace($escapers, $replacements, $row['ibu_method']); - $data .= '","color_method":"' . str_replace($escapers, $replacements, $row['color_method']); - $data .= '","brix_correction":' . floatval($row['brix_correction']); + $data .= ',"factor_wethop":' . $row['factor_wethop']; + $data .= ',"ibu_method":' . $row['ibu_method']; + $data .= ',"color_method":' . $row['color_method']; + $data .= ',"brix_correction":' . floatval($row['brix_correction']); $data .= ',"grain_absorbtion":' . floatval($row['grain_absorbtion']); $data .= ',"default_water":"' . str_replace($escapers, $replacements, $default_water); $data .= '"}';