From cb7759574700a667e49b623a1ece9f4066c82311 Mon Sep 17 00:00:00 2001 From: YuFei Zhu Date: Mon, 30 Apr 2012 17:14:44 +0100 Subject: [PATCH] added auth token for delete offline messages check for csrf --- src/messenger/webim/libs/common.php | 2 +- src/messenger/webim/operator/canned.php | 2 ++ src/messenger/webim/view/canned.php | 4 ++-- 3 files changed, 5 insertions(+), 3 deletions(-) diff --git a/src/messenger/webim/libs/common.php b/src/messenger/webim/libs/common.php index 71e33f7c..36f55e70 100644 --- a/src/messenger/webim/libs/common.php +++ b/src/messenger/webim/libs/common.php @@ -779,7 +779,7 @@ function csrfchecktoken(){ die("CSRF failure"); } - } else if($_GET['act'] == 'del' && $_GET['csrf_token'] != $_SESSION['csrf_token']){ + } else if(($_GET['act'] == 'del' || $_GET['act'] == 'delete') && $_GET['csrf_token'] != $_SESSION['csrf_token']){ die("CSRF failure"); } diff --git a/src/messenger/webim/operator/canned.php b/src/messenger/webim/operator/canned.php index dd01f4c2..f21fc0a5 100644 --- a/src/messenger/webim/operator/canned.php +++ b/src/messenger/webim/operator/canned.php @@ -26,6 +26,8 @@ require_once('../libs/settings.php'); require_once('../libs/groups.php'); require_once('../libs/pagination.php'); +csrfchecktoken(); + $operator = check_login(); force_password($operator); diff --git a/src/messenger/webim/view/canned.php b/src/messenger/webim/view/canned.php index 9a7eddea..55c0f926 100644 --- a/src/messenger/webim/view/canned.php +++ b/src/messenger/webim/view/canned.php @@ -95,7 +95,7 @@ if( $page['pagination.items'] ) { , - &group="> + &group="> \ No newline at end of file +?>