error("You can't split discussions!");
}
- if (!empty($name)) { // User has confirmed the prune
+ if (!empty($name) && confirm_sesskey()) { // User has confirmed the prune
$newdiscussion = new object();
$newdiscussion->course = $discussion->course;
<td align="center" colspan="2">
<input type="hidden" name="prune" value="<?php p($prune) ?>" />
<input type="hidden" name="confirm" value="<?php p($prune) ?>" />
+ <input type="hidden" name="sesskey" value="<?php echo sesskey() ?>" />
<input type="submit" value="<?php print_string('prune', 'forum'); ?>" />
</td>
</tr>