diff --git a/src/trigger/f0ckrand.js b/src/trigger/f0ckrand.js index db89e7c..6f05ef6 100644 --- a/src/trigger/f0ckrand.js +++ b/src/trigger/f0ckrand.js @@ -5,20 +5,16 @@ module.exports = (lib) => { level: 0, active: 1, func: (e) => { - let args = e.message.split(" "); + let args = lib.sql.escape(e.message).split(" "); args.shift(); args.shift(); let query = "select `id`,`username` from `f0ck`.`items` order by rand() "; - - if(args.length > 0) { - query += "where `username` = ? ".repeat(args.length); - } - + if(args.length > 0) + query += "where `username` = '" + args.join("' || `username` = '"); query += "limit 1"; - console.log(query); - lib.sql.query(query, args, (err, rows, fields) => { + lib.sql.query(query, (err, rows, fields) => { if(!err) e.reply("f0ckrnd: "+lib.cfg.main.url+"/"+rows[0].id+" by: "+rows[0].username); });