diff options
author | plegall <plg@piwigo.org> | 2009-12-17 01:02:44 +0000 |
---|---|---|
committer | plegall <plg@piwigo.org> | 2009-12-17 01:02:44 +0000 |
commit | 587aaa02102e97f71a7dfb07ec48efc36593b924 (patch) | |
tree | 3fe61c33a0b3cbcc08883b1939c78046ce8729c5 /admin/plugins_new.php | |
parent | f2fa6c16d92bbf36820645cc6a39d2a128f572fc (diff) |
bug 1328: implements check_pwg_token at plugin management level.
git-svn-id: http://piwigo.org/svn/branches/2.0@4506 68402e56-0260-453c-a942-63ccdbb3a9ee
Diffstat (limited to 'admin/plugins_new.php')
-rw-r--r-- | admin/plugins_new.php | 6 |
1 files changed, 5 insertions, 1 deletions
diff --git a/admin/plugins_new.php b/admin/plugins_new.php index 56b09d097..857f75bc5 100644 --- a/admin/plugins_new.php +++ b/admin/plugins_new.php @@ -38,6 +38,8 @@ $plugins = new plugins(); //------------------------------------------------------automatic installation if (isset($_GET['revision']) and isset($_GET['extension']) and !is_adviser()) { + check_pwg_token(); + $install_status = $plugins->extract_plugin_files('install', $_GET['revision'], $_GET['extension']); redirect($base_url.'&installstatus='.$install_status); @@ -110,7 +112,9 @@ if ($plugins->get_server_plugins(true)) $url_auto_install = htmlentities($base_url) . '&revision=' . $plugin['revision_id'] - . '&extension=' . $plugin['extension_id']; + . '&extension=' . $plugin['extension_id'] + . '&pwg_token='.get_pwg_token() + ; $template->append('plugins', array( 'EXT_NAME' => $plugin['extension_name'], |