MDL-44082 mod_chat: added a security check for users already in the c…

…hat activity
1 parent aea3249 commit 7748e17207b1a28118d9dc622878da22f956d3fe @andyjdavis andyjdavis committed with danpoltawski
Showing with 5 additions and 0 deletions.
  1. +5 −0 mod/chat/chat_ajax.php
5 mod/chat/chat_ajax.php
@@ -52,6 +52,11 @@
$PAGE->set_cm($cm, $course, $chat);
$PAGE->set_url('/mod/chat/chat_ajax.php', array('chat_sid'=>$chat_sid));
+require_login($course, false, $cm);
+$context = context_module::instance($cm->id);
+require_capability('mod/chat:chat', $context);
header('Expires: Sun, 28 Dec 1997 09:32:45 GMT');
header('Last-Modified: '.gmdate('D, d M Y H:i:s').' GMT');

