File tree 2 files changed +17
-0
lines changed
2 files changed +17
-0
lines changed Original file line number Diff line number Diff line change 231
231
$ agenda_ajax_url .= '&session_id= ' .intval ($ _GET ['session_id ' ]);
232
232
}
233
233
234
+ $ agenda_ajax_url .= '&sec_token= ' .Security::get_token ();
235
+
234
236
$ tpl ->assign ('web_agenda_ajax_url ' , $ agenda_ajax_url );
235
237
236
238
$ form = new FormValidator (
Original file line number Diff line number Diff line change 35
35
if (!$ agenda ->getIsAllowedToEdit ()) {
36
36
break ;
37
37
}
38
+ if (false === Security::check_token ('get ' )) {
39
+ exit ;
40
+ }
38
41
$ add_as_announcement = isset ($ _REQUEST ['add_as_annonuncement ' ]) ? $ _REQUEST ['add_as_annonuncement ' ] : null ;
39
42
$ title = isset ($ _REQUEST ['title ' ]) ? $ _REQUEST ['title ' ] : null ;
40
43
$ content = isset ($ _REQUEST ['content ' ]) ? $ _REQUEST ['content ' ] : null ;
59
62
if (!$ agenda ->getIsAllowedToEdit ()) {
60
63
break ;
61
64
}
65
+ if (false === Security::check_token ('get ' )) {
66
+ exit ;
67
+ }
62
68
$ id_list = explode ('_ ' , $ _REQUEST ['id ' ]);
63
69
$ id = $ id_list [1 ];
64
70
$ agenda ->editEvent (
74
80
if (!$ agenda ->getIsAllowedToEdit ()) {
75
81
break ;
76
82
}
83
+ if (false === Security::check_token ('get ' )) {
84
+ exit ;
85
+ }
77
86
$ id_list = explode ('_ ' , $ _REQUEST ['id ' ]);
78
87
$ id = $ id_list [1 ];
79
88
$ deleteAllEventsFromSerie = isset ($ _REQUEST ['delete_all_events ' ]) ? true : false ;
83
92
if (!$ agenda ->getIsAllowedToEdit ()) {
84
93
break ;
85
94
}
95
+ if (false === Security::check_token ('get ' )) {
96
+ exit ;
97
+ }
86
98
$ minute_delta = $ _REQUEST ['minute_delta ' ];
87
99
$ id = explode ('_ ' , $ _REQUEST ['id ' ]);
88
100
$ id = $ id [1 ];
92
104
if (!$ agenda ->getIsAllowedToEdit ()) {
93
105
break ;
94
106
}
107
+ if (false === Security::check_token ('get ' )) {
108
+ exit ;
109
+ }
95
110
$ minute_delta = $ _REQUEST ['minute_delta ' ];
96
111
$ allDay = $ _REQUEST ['all_day ' ];
97
112
$ id = explode ('_ ' , $ _REQUEST ['id ' ]);
You can’t perform that action at this time.
0 commit comments