MDL-58635 blogs: check edited blog belongs to current user
This commit is contained in:
committed by
David Monllao
parent
5743df7428
commit
27795d1eed
@@ -53,11 +53,11 @@ $action = (empty($id)) ? 'add' : 'edit';
|
||||
|
||||
$external = new stdClass();
|
||||
|
||||
// Check that this id exists.
|
||||
if (!empty($id) && !$DB->record_exists('blog_external', array('id' => $id))) {
|
||||
print_error('wrongexternalid', 'blog');
|
||||
} else if (!empty($id)) {
|
||||
$external = $DB->get_record('blog_external', array('id' => $id));
|
||||
// Retrieve the external blog record.
|
||||
if (!empty($id)) {
|
||||
if (!$external = $DB->get_record('blog_external', array('id' => $id, 'userid' => $USER->id))) {
|
||||
print_error('wrongexternalid', 'blog');
|
||||
}
|
||||
}
|
||||
|
||||
$strformheading = ($action == 'edit') ? get_string('editexternalblog', 'blog') : get_string('addnewexternalblog', 'blog');
|
||||
|
||||
@@ -180,6 +180,7 @@ $string['viewmyentriesaboutcourse'] = 'View my entries about this course';
|
||||
$string['viewsiteentries'] = 'View all entries';
|
||||
$string['viewuserentries'] = 'View all entries by {$a}';
|
||||
$string['worldblogs'] = 'The world can read entries set to be world-accessible';
|
||||
$string['wrongexternalid'] = 'Wrong external blog id';
|
||||
$string['wrongpostid'] = 'Wrong blog post id';
|
||||
$string['page-blog-edit'] = 'Blog editing pages';
|
||||
$string['page-blog-index'] = 'Blog listing pages';
|
||||
|
||||
Reference in New Issue
Block a user