diff --git a/blocks/admin_bookmarks/block_admin_bookmarks.php b/blocks/admin_bookmarks/block_admin_bookmarks.php index 01350256fc3..1b7d47880ca 100644 --- a/blocks/admin_bookmarks/block_admin_bookmarks.php +++ b/blocks/admin_bookmarks/block_admin_bookmarks.php @@ -32,8 +32,6 @@ class block_admin_bookmarks extends block_base { /** @var string */ public $blockname = null; - /** @var bool */ - protected $contentgenerated = false; /** @var bool|null */ protected $docked = null; @@ -74,9 +72,10 @@ class block_admin_bookmarks extends block_base { global $CFG; // First check if we have already generated, don't waste cycles - if ($this->contentgenerated === true) { + if ($this->content !== null) { return $this->content; } + $this->content = new stdClass(); if (get_user_preferences('admin_bookmarks')) { diff --git a/blocks/admin_bookmarks/create.php b/blocks/admin_bookmarks/create.php index 71156cbc466..07ed88f8603 100644 --- a/blocks/admin_bookmarks/create.php +++ b/blocks/admin_bookmarks/create.php @@ -30,7 +30,8 @@ $context = context_system::instance(); $PAGE->set_context($context); $adminroot = admin_get_root(false, false); // settings not required - only pages -if ($section = optional_param('section', '', PARAM_SAFEDIR) and confirm_sesskey()) { +// We clean section with safe path here for compatibility with external pages that include a slash in their name. +if ($section = optional_param('section', '', PARAM_SAFEPATH) and confirm_sesskey()) { if (get_user_preferences('admin_bookmarks')) { $bookmarks = explode(',', get_user_preferences('admin_bookmarks')); diff --git a/blocks/admin_bookmarks/delete.php b/blocks/admin_bookmarks/delete.php index cd3d03207f0..a1d8f14ebab 100644 --- a/blocks/admin_bookmarks/delete.php +++ b/blocks/admin_bookmarks/delete.php @@ -31,7 +31,8 @@ $context = context_system::instance(); $PAGE->set_context($context); $adminroot = admin_get_root(false, false); // settings not required - only pages -if ($section = optional_param('section', '', PARAM_SAFEDIR) and confirm_sesskey()) { +// We clean section with safe path here for compatibility with external pages that include a slash in their name. +if ($section = optional_param('section', '', PARAM_SAFEPATH) and confirm_sesskey()) { if (get_user_preferences('admin_bookmarks')) {