From 69b8ba4c4cd4f191b1bb699871d3b59fc1c39d6e Mon Sep 17 00:00:00 2001 From: moodler Date: Fri, 6 May 2005 03:11:58 +0000 Subject: [PATCH] Added sesskey checking (SC #113) --- admin/delete.php | 17 ++++++++++++----- 1 file changed, 12 insertions(+), 5 deletions(-) diff --git a/admin/delete.php b/admin/delete.php index 37d9979a576..2e70e5ae345 100644 --- a/admin/delete.php +++ b/admin/delete.php @@ -7,22 +7,29 @@ require_login(); + $sure = optional_param('sure', ''); + $reallysure = optional_param('reallysure', ''); + if (!isadmin()) { error('You must be admin to use this script!'); } $deletedir = $CFG->dataroot; // The directory to delete! - if (!$sure) { - notice_yesno ('Are you completely sure you want to delete everything inside the directory '. $deletedir .' ?', 'delete.php?sure=yes', 'index.php'); + if (empty($sure)) { + notice_yesno ('Are you completely sure you want to delete everything inside the directory '. $deletedir .' ?', 'delete.php?sure=yes&sesskey='.sesskey(), 'index.php'); exit; } - if (!$reallysure) { - notice_yesno ('Are you REALLY REALLY completely sure you want to delete everything inside the directory '. $deletedir .' (this includes all user images, and any other course files that have been created) ?', 'delete.php?sure=yes&reallysure=yes', 'index.php'); + if (empty($reallysure)) { + notice_yesno ('Are you REALLY REALLY completely sure you want to delete everything inside the directory '. $deletedir .' (this includes all user images, and any other course files that have been created) ?', 'delete.php?sure=yes&reallysure=yes&sesskey='.sesskey(), 'index.php'); exit; } + if (!confirm_sesskey()) { + error('This script was called wrongly'); + } + /// OK, here goes ... delete_subdirectories($deletedir); @@ -60,4 +67,4 @@ function delete_subdirectories($rootdir) { closedir($dir); } -?> \ No newline at end of file +?>