From 2404aa0a8597dd979722ea4624b48179cf3ff1fb Mon Sep 17 00:00:00 2001 From: Petr Skoda Date: Thu, 18 Mar 2010 22:53:45 +0000 Subject: [PATCH] MDL-21859 fixed sesskey protection on email actions --- user/view.php | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/user/view.php b/user/view.php index 6b6c048056f..9186d777b5c 100644 --- a/user/view.php +++ b/user/view.php @@ -242,11 +242,11 @@ $emailswitch = ''; if (has_capability('moodle/course:useremail', $coursecontext) or $currentuser) { /// Can use the enable/disable email stuff - if (!empty($enable)) { /// Recieved a parameter to enable the email address + if (!empty($enable) and confirm_sesskey()) { /// Recieved a parameter to enable the email address set_field('user', 'emailstop', 0, 'id', $user->id); $user->emailstop = 0; } - if (!empty($disable)) { /// Recieved a parameter to disable the email address + if (!empty($disable) and confirm_sesskey()) { /// Recieved a parameter to disable the email address set_field('user', 'emailstop', 1, 'id', $user->id); $user->emailstop = 1; } @@ -265,7 +265,7 @@ $switchpix = 'email.gif'; } $emailswitch = " id&course=$course->id&$switchparam=1\">". + "href=\"view.php?id=$user->id&course=$course->id&$switchparam=1&sesskey=".sesskey()."\">". "pixpath/t/$switchpix\" alt=\"$switchclick\" />"; } else if ($currentuser) { /// Can only re-enable an email this way @@ -275,7 +275,7 @@ $switchclick = get_string('emailenableclick'); $emailswitch = " (id&course=$course->id&enable=1\">$switchtitle)"; + "href=\"view.php?id=$user->id&course=$course->id&enable=1&sesskey=".sesskey()."\">$switchtitle)"; } }