From 719593e83973c136f222f7c8db0c91ec8aca9e5f Mon Sep 17 00:00:00 2001 From: stronk7 Date: Sat, 2 Oct 2004 22:44:25 +0000 Subject: [PATCH] admin/backup.php is now using sesskey. --- admin/backup.php | 4 ++++ admin/configure.php | 2 +- admin/index.php | 2 +- backup/config.html | 1 + backup/log.php | 4 ++-- 5 files changed, 9 insertions(+), 4 deletions(-) diff --git a/admin/backup.php b/admin/backup.php index 608f39e0689..d97e5239e2c 100644 --- a/admin/backup.php +++ b/admin/backup.php @@ -15,6 +15,10 @@ error("Site isn't defined!"); } + if (!confirm_sesskey()) { + error(get_string('confirmsesskeybad', 'error')); + } + //Initialise error variables $error = false; $sche_destination_error = ""; diff --git a/admin/configure.php b/admin/configure.php index f51b70fb59e..1059df1de68 100644 --- a/admin/configure.php +++ b/admin/configure.php @@ -37,7 +37,7 @@ $table->data[] = array("".get_string("managefilters")."", get_string("adminhelpmanagefilters")); if (!isset($CFG->disablescheduledbackups)) { - $table->data[] = array("".get_string("backup")."", + $table->data[] = array("sesskey\">".get_string("backup")."", get_string("adminhelpbackup")); } diff --git a/admin/index.php b/admin/index.php index 1a5047369ea..106e2b7feda 100644 --- a/admin/index.php +++ b/admin/index.php @@ -285,7 +285,7 @@ $configdata .= " ".get_string("managefilters")." - ". get_string("adminhelpmanagefilters")."
"; if (!isset($CFG->disablescheduledbackups)) { - $configdata .= " ".get_string("backup")." - ". + $configdata .= " sesskey\">".get_string("backup")." - ". get_string("adminhelpbackup")."
"; } $configdata .= " ". get_string("editorsettings") ." - ". diff --git a/backup/config.html b/backup/config.html index 5dabf688874..9a4c9b6289c 100644 --- a/backup/config.html +++ b/backup/config.html @@ -82,6 +82,7 @@ $keep_array[500] = "500"; ?>
+sesskey."\">"; ?> diff --git a/backup/log.php b/backup/log.php index cf67b31f0ed..83af67c71ad 100644 --- a/backup/log.php +++ b/backup/log.php @@ -40,7 +40,7 @@ print_header("$site->shortname: $strconfiguration: $strbackup", $site->fullname, "admin/index.php\">$stradmin -> ". "admin/configure.php\">$strconfiguration -> ". - "admin/backup.php\">$strbackup -> ". + "admin/backup.php?sesskey=$USER->sesskey\">$strbackup -> ". $strlogs); print_heading($backuploglaststatus); @@ -86,7 +86,7 @@ print_header("$site->shortname: $strconfiguration: $strbackup", $site->fullname, "admin/index.php\">$stradmin -> ". "admin/configure.php\">$strconfiguration -> ". - "admin/backup.php\">$strbackup -> ". + "admin/backup.php?sesskey=$USER->sesskey\">$strbackup -> ". "$strlogs -> ". $strbackupdetails);