bug 1328: implements check_pwg_token at plugin management level.
git-svn-id: http://piwigo.org/svn/branches/2.0@4506 68402e56-0260-453c-a942-63ccdbb3a9ee
This commit is contained in:
parent
f2fa6c16d9
commit
587aaa0210
3 changed files with 14 additions and 3 deletions
|
@ -38,6 +38,8 @@ $plugins = new plugins();
|
||||||
//--------------------------------------------------perform requested actions
|
//--------------------------------------------------perform requested actions
|
||||||
if (isset($_GET['action']) and isset($_GET['plugin']) and !is_adviser())
|
if (isset($_GET['action']) and isset($_GET['plugin']) and !is_adviser())
|
||||||
{
|
{
|
||||||
|
check_pwg_token();
|
||||||
|
|
||||||
$page['errors'] = $plugins->perform_action($_GET['action'], $_GET['plugin']);
|
$page['errors'] = $plugins->perform_action($_GET['action'], $_GET['plugin']);
|
||||||
|
|
||||||
if (empty($page['errors']))
|
if (empty($page['errors']))
|
||||||
|
@ -96,7 +98,7 @@ foreach($plugins->fs_plugins as $plugin_id => $fs_plugin)
|
||||||
array('NAME' => $display_name,
|
array('NAME' => $display_name,
|
||||||
'VERSION' => $fs_plugin['version'],
|
'VERSION' => $fs_plugin['version'],
|
||||||
'DESCRIPTION' => $desc,
|
'DESCRIPTION' => $desc,
|
||||||
'U_ACTION' => $base_url.'&plugin='.$plugin_id);
|
'U_ACTION' => $base_url.'&plugin='.$plugin_id.'&pwg_token='.get_pwg_token());
|
||||||
|
|
||||||
if (isset($plugins->db_plugins_by_id[$plugin_id]))
|
if (isset($plugins->db_plugins_by_id[$plugin_id]))
|
||||||
{
|
{
|
||||||
|
|
|
@ -38,6 +38,8 @@ $plugins = new plugins();
|
||||||
//------------------------------------------------------automatic installation
|
//------------------------------------------------------automatic installation
|
||||||
if (isset($_GET['revision']) and isset($_GET['extension']) and !is_adviser())
|
if (isset($_GET['revision']) and isset($_GET['extension']) and !is_adviser())
|
||||||
{
|
{
|
||||||
|
check_pwg_token();
|
||||||
|
|
||||||
$install_status = $plugins->extract_plugin_files('install', $_GET['revision'], $_GET['extension']);
|
$install_status = $plugins->extract_plugin_files('install', $_GET['revision'], $_GET['extension']);
|
||||||
|
|
||||||
redirect($base_url.'&installstatus='.$install_status);
|
redirect($base_url.'&installstatus='.$install_status);
|
||||||
|
@ -110,7 +112,9 @@ if ($plugins->get_server_plugins(true))
|
||||||
|
|
||||||
$url_auto_install = htmlentities($base_url)
|
$url_auto_install = htmlentities($base_url)
|
||||||
. '&revision=' . $plugin['revision_id']
|
. '&revision=' . $plugin['revision_id']
|
||||||
. '&extension=' . $plugin['extension_id'];
|
. '&extension=' . $plugin['extension_id']
|
||||||
|
. '&pwg_token='.get_pwg_token()
|
||||||
|
;
|
||||||
|
|
||||||
$template->append('plugins', array(
|
$template->append('plugins', array(
|
||||||
'EXT_NAME' => $plugin['extension_name'],
|
'EXT_NAME' => $plugin['extension_name'],
|
||||||
|
|
|
@ -37,6 +37,8 @@ $plugins = new plugins();
|
||||||
//-----------------------------------------------------------automatic upgrade
|
//-----------------------------------------------------------automatic upgrade
|
||||||
if (isset($_GET['plugin']) and isset($_GET['revision']) and !is_adviser())
|
if (isset($_GET['plugin']) and isset($_GET['revision']) and !is_adviser())
|
||||||
{
|
{
|
||||||
|
check_pwg_token();
|
||||||
|
|
||||||
$plugin_id = $_GET['plugin'];
|
$plugin_id = $_GET['plugin'];
|
||||||
$revision = $_GET['revision'];
|
$revision = $_GET['revision'];
|
||||||
|
|
||||||
|
@ -48,6 +50,7 @@ if (isset($_GET['plugin']) and isset($_GET['revision']) and !is_adviser())
|
||||||
redirect($base_url
|
redirect($base_url
|
||||||
. '&revision=' . $revision
|
. '&revision=' . $revision
|
||||||
. '&plugin=' . $plugin_id
|
. '&plugin=' . $plugin_id
|
||||||
|
. '&pwg_token='.get_pwg_token()
|
||||||
. '&reactivate=true');
|
. '&reactivate=true');
|
||||||
}
|
}
|
||||||
|
|
||||||
|
@ -133,7 +136,9 @@ if ($plugins->get_server_plugins())
|
||||||
// Plugin need upgrade
|
// Plugin need upgrade
|
||||||
$url_auto_update = $base_url
|
$url_auto_update = $base_url
|
||||||
. '&revision=' . $plugin_info['revision_id']
|
. '&revision=' . $plugin_info['revision_id']
|
||||||
. '&plugin=' . $plugin_id;
|
. '&plugin=' . $plugin_id
|
||||||
|
. '&pwg_token='.get_pwg_token()
|
||||||
|
;
|
||||||
|
|
||||||
$template->append('plugins_not_uptodate', array(
|
$template->append('plugins_not_uptodate', array(
|
||||||
'EXT_NAME' => $fs_plugin['name'],
|
'EXT_NAME' => $fs_plugin['name'],
|
||||||
|
|
Loading…
Add table
Reference in a new issue