Skip to content

Commit

Permalink
Protect message settings with sesskey. MDL-16688 ; merged from 19_STABLE
Browse files Browse the repository at this point in the history
  • Loading branch information
stronk7 committed Sep 25, 2008
1 parent 13d974c commit d6b4fed
Show file tree
Hide file tree
Showing 2 changed files with 5 additions and 2 deletions.
2 changes: 1 addition & 1 deletion message/lib.php
Original file line number Diff line number Diff line change
Expand Up @@ -205,7 +205,7 @@ function message_print_search() {
function message_print_settings() {
global $USER;

if ($frm = data_submitted()) {
if ($frm = data_submitted() and confirm_sesskey()) {

$pref = array();
$pref['message_showmessagewindow'] = (isset($frm->showmessagewindow)) ? '1' : '0';
Expand Down
5 changes: 4 additions & 1 deletion message/settings.html
Original file line number Diff line number Diff line change
@@ -1,5 +1,8 @@
<form id="message_settings" action="index.php" method="post">
<div><input type="hidden" name="tab" value="settings" /></div>
<div>
<input type="hidden" name="tab" value="settings" />
<input type="hidden" name="sesskey" value="<?php echo sesskey() ?>" />
</div>


<table cellpadding="5" class="message_form boxaligncenter">
Expand Down

0 comments on commit d6b4fed

Please sign in to comment.