mirror of
https://github.com/Piwigo/Piwigo.git
synced 2026-08-11 11:13:02 +02:00
bug 1328: backport the pwg_token on trunk
bug 1329: backport the check_input_parameter on trunk feature 1026: add pwg_token feature for edit/delete comment. Heavy refactoring on this feature to make the code simpler and easier to maintain (I hope). git-svn-id: http://piwigo.org/svn/trunk@5195 68402e56-0260-453c-a942-63ccdbb3a9ee
This commit is contained in:
@@ -166,23 +166,25 @@ $validated_clause.'
|
||||
|
||||
if (can_manage_comment('delete', $row['author_id']))
|
||||
{
|
||||
$tpl_comment['U_DELETE'] =
|
||||
add_url_params($url_self,
|
||||
array(
|
||||
'action'=>'delete_comment',
|
||||
'comment_to_delete'=>$row['id']
|
||||
)
|
||||
);
|
||||
$tpl_comment['U_DELETE'] = add_url_params(
|
||||
$url_self,
|
||||
array(
|
||||
'action'=>'delete_comment',
|
||||
'comment_to_delete'=>$row['id'],
|
||||
'pwg_token' => get_pwg_token(),
|
||||
)
|
||||
);
|
||||
}
|
||||
if (can_manage_comment('edit', $row['author_id']))
|
||||
{
|
||||
$tpl_comment['U_EDIT'] =
|
||||
add_url_params($url_self,
|
||||
array(
|
||||
'action'=>'edit_comment',
|
||||
'comment_to_edit'=>$row['id']
|
||||
)
|
||||
);
|
||||
$tpl_comment['U_EDIT'] = add_url_params(
|
||||
$url_self,
|
||||
array(
|
||||
'action'=>'edit_comment',
|
||||
'comment_to_edit'=>$row['id'],
|
||||
'pwg_token' => get_pwg_token(),
|
||||
)
|
||||
);
|
||||
if (isset($edit_comment) and ($row['id'] == $edit_comment))
|
||||
{
|
||||
$tpl_comment['IN_EDIT'] = true;
|
||||
@@ -195,12 +197,14 @@ $validated_clause.'
|
||||
{
|
||||
if ($row['validated'] != 'true')
|
||||
{
|
||||
$tpl_comment['U_VALIDATE'] =
|
||||
add_url_params($url_self,
|
||||
array('action' => 'validate_comment',
|
||||
'comment_to_validate' => $row['id']
|
||||
)
|
||||
);
|
||||
$tpl_comment['U_VALIDATE'] = add_url_params(
|
||||
$url_self,
|
||||
array(
|
||||
'action' => 'validate_comment',
|
||||
'comment_to_validate' => $row['id'],
|
||||
'pwg_token' => get_pwg_token(),
|
||||
)
|
||||
);
|
||||
}
|
||||
}
|
||||
$template->append('comments', $tpl_comment);
|
||||
|
||||
Reference in New Issue
Block a user