Skip to content

Commit

Permalink
admin/admin.php is now using sesskey.
Browse files Browse the repository at this point in the history
Merged from MOODLE_14_STABLE
  • Loading branch information
stronk7 committed Oct 2, 2004
1 parent d36f8be commit ad97e35
Show file tree
Hide file tree
Showing 4 changed files with 7 additions and 2 deletions.
1 change: 1 addition & 0 deletions admin/admin.html
@@ -1,6 +1,7 @@

<form name="adminform" id="adminform" method="post" action="admin.php">
<input type="hidden" name="previoussearch" value="<?php echo $previoussearch ?>">
<input type="hidden" name="sesskey" value="<?php echo $USER->sesskey ?>">
<table align="center" border="0" cellpadding="5" cellspacing="0">
<tr>
<td valign="top">
Expand Down
4 changes: 4 additions & 0 deletions admin/admin.php
Expand Up @@ -19,6 +19,10 @@
error("You must be an administrator to use this page.");
}

if (!confirm_sesskey()) {
error(get_string('confirmsesskeybad', 'error'));
}

$primaryadmin = get_admin();

/// If you want any administrator to have the ability to assign admin
Expand Down
2 changes: 1 addition & 1 deletion admin/index.php
Expand Up @@ -331,7 +331,7 @@
" <img src=\"../pix/t/user.gif\" height=\"11\" width=\"11\" alt=\"\"></font><br />";
$userdata .= "<font size=+1>&nbsp;</font><a href=\"creators.php\">".get_string("assigncreators")."</a> - <font size=\"1\">".
get_string("adminhelpassigncreators")."</font><br />";
$userdata .= "<font size=+1>&nbsp;</font><a href=\"admin.php\">".get_string("assignadmins")."</a> - <font size=\"1\">".
$userdata .= "<font size=+1>&nbsp;</font><a href=\"admin.php?sesskey=$USER->sesskey\">".get_string("assignadmins")."</a> - <font size=\"1\">".
get_string("adminhelpassignadmins")."</font><br />";

$table->data[] = array("<font size=+1><b><a href=\"users.php\">".get_string("users")."</a></b>", $userdata);
Expand Down
2 changes: 1 addition & 1 deletion admin/users.php
Expand Up @@ -42,7 +42,7 @@
get_string("adminhelpassignteachers")." <img src=\"../pix/t/user.gif\" height=\"11\" width=\"11\" alt=\"\" />");
$table->data[] = array("<b><a href=\"creators.php\">".get_string("assigncreators")."</a></b>",
get_string("adminhelpassigncreators"));
$table->data[] = array("<b><a href=\"admin.php\">".get_string("assignadmins")."</a></b>",
$table->data[] = array("<b><a href=\"admin.php?sesskey=$USER->sesskey\">".get_string("assignadmins")."</a></b>",
get_string("adminhelpassignadmins"));

print_table($table);
Expand Down

0 comments on commit ad97e35

Please sign in to comment.