]> git.openstreetmap.org Git - rails.git/blobdiff - app/controllers/swf_controller.rb
Merge commit 'git-svn'
[rails.git] / app / controllers / swf_controller.rb
index 9a4516016700eaa2986ee1ebd06ccccbfa6e480c..33e2ee4a6c085abf228b6e8c36c38d1ea093a21b 100644 (file)
@@ -1,5 +1,6 @@
 class SwfController < ApplicationController
-  before_filter :check_availability
+       session :off
+       before_filter :check_availability
 
 # to log:
 # RAILS_DEFAULT_LOGGER.error("Args: #{args[0]}, #{args[1]}, #{args[2]}, #{args[3]}")
@@ -45,12 +46,11 @@ class SwfController < ApplicationController
                lastfile='-1'
        
                if params['token']
-                       token=sqlescape(params['token'])
+                        user=User.authenticate(:token => params[:token])
                        sql="SELECT gps_points.latitude*0.000001 AS lat,gps_points.longitude*0.000001 AS lon,gpx_files.id AS fileid,UNIX_TIMESTAMP(gps_points.timestamp) AS ts "+
-                                " FROM gpx_files,gps_points,users "+
+                                " FROM gpx_files,gps_points "+
                                 "WHERE gpx_files.id=gpx_id "+
-                                "  AND gpx_files.user_id=users.id "+
-                                "  AND token='#{token}' "+
+                                "  AND gpx_files.user_id=#{user.id} "+
                                 "  AND (gps_points.longitude BETWEEN #{xminr} AND #{xmaxr}) "+
                                 "  AND (gps_points.latitude BETWEEN #{yminr} AND #{ymaxr}) "+
                                 "  AND (gps_points.timestamp IS NOT NULL) "+
@@ -94,7 +94,7 @@ class SwfController < ApplicationController
                        sql="SELECT cn1.latitude AS lat1,cn1.longitude AS lon1,"+
                                "               cn2.latitude AS lat2,cn2.longitude AS lon2 "+
                                "  FROM current_segments "+
-                               "       LEFT OUTER JOIN current_way_segments"+
+                               "       LEFT OUTER JOIN current_way_nodes"+
                                "       ON segment_id=current_segments.id,"+
                                "       current_nodes AS cn1,current_nodes AS cn2"+
                                " WHERE (cn1.longitude BETWEEN #{xmin} AND #{xmax})"+