forked from Wavyzz/dolibarr
Fix: creation et verification d'un jeton alatoire afin de valider une requete POST, voici la ligne ajouter dans une requete POST
print '<input type="hidden" name="token" value="'.$_SESSION['newtoken'].'">';
This commit is contained in:
@@ -34,12 +34,6 @@ $langs->load("admin");
|
||||
if (! empty($_SERVER['HTTP_REFERER']) && !eregi(DOL_MAIN_URL_ROOT, $_SERVER['HTTP_REFERER']))
|
||||
accessforbidden();
|
||||
|
||||
//Todo: Verification de la presence et de la validite du jeton pr<70>c<EFBFBD>dent
|
||||
if (isset($_POST['token']) && isset($_SESSION['oldtoken']))
|
||||
{
|
||||
if ($_POST['token'] != $_SESSION['oldtoken']) accessforbidden();
|
||||
}
|
||||
|
||||
if (!$user->admin)
|
||||
accessforbidden();
|
||||
|
||||
|
||||
Reference in New Issue
Block a user