Changeset 4506


Ignore:
Timestamp:
Dec 17, 2009, 2:02:44 AM (11 years ago)
Author:
plg
Message:

bug 1328: implements check_pwg_token at plugin management level.

Location:
branches/2.0/admin
Files:
3 edited

Legend:

Unmodified
Added
Removed
  • branches/2.0/admin/plugins_list.php

    r3949 r4506  
    3939if (isset($_GET['action']) and isset($_GET['plugin']) and !is_adviser())
    4040{
     41  check_pwg_token();
     42 
    4143  $page['errors'] = $plugins->perform_action($_GET['action'], $_GET['plugin']);
    4244
     
    9799          'VERSION' => $fs_plugin['version'],
    98100          'DESCRIPTION' => $desc,
    99           'U_ACTION' => $base_url.'&plugin='.$plugin_id);
     101          'U_ACTION' => $base_url.'&plugin='.$plugin_id.'&pwg_token='.get_pwg_token());
    100102
    101103  if (isset($plugins->db_plugins_by_id[$plugin_id]))
  • branches/2.0/admin/plugins_new.php

    r3144 r4506  
    3939if (isset($_GET['revision']) and isset($_GET['extension']) and !is_adviser())
    4040{
     41  check_pwg_token();
     42 
    4143  $install_status = $plugins->extract_plugin_files('install', $_GET['revision'], $_GET['extension']);
    4244
     
    111113    $url_auto_install = htmlentities($base_url)
    112114      . '&revision=' . $plugin['revision_id']
    113       . '&extension=' . $plugin['extension_id'];
     115      . '&extension=' . $plugin['extension_id']
     116      . '&pwg_token='.get_pwg_token()
     117    ;
    114118
    115119    $template->append('plugins', array(
  • branches/2.0/admin/plugins_update.php

    r3144 r4506  
    3838if (isset($_GET['plugin']) and isset($_GET['revision']) and !is_adviser())
    3939{
     40  check_pwg_token();
     41 
    4042  $plugin_id = $_GET['plugin'];
    4143  $revision = $_GET['revision'];
     
    4951      . '&revision=' . $revision
    5052      . '&plugin=' . $plugin_id
     53      . '&pwg_token='.get_pwg_token()
    5154      . '&reactivate=true');
    5255  }
     
    134137        $url_auto_update = $base_url
    135138          . '&revision=' . $plugin_info['revision_id']
    136           . '&plugin=' . $plugin_id;
     139          . '&plugin=' . $plugin_id
     140          . '&pwg_token='.get_pwg_token()
     141          ;
    137142
    138143        $template->append('plugins_not_uptodate', array(
Note: See TracChangeset for help on using the changeset viewer.