From: Nicolas Connault Date: Thu, 29 Oct 2009 09:01:58 +0000 (+0000) Subject: MDL-20663 (Correctly) added sesskey confirmation X-Git-Url: http://git.mjollnir.org/gw?a=commitdiff_plain;h=9d90b9980e33f8f6bb2e54b0fb33ee8026a8defc;p=moodle.git MDL-20663 (Correctly) added sesskey confirmation --- diff --git a/grade/report/grader/ajax_callbacks.php b/grade/report/grader/ajax_callbacks.php index 0c7ae059a4..a1ef4445e3 100644 --- a/grade/report/grader/ajax_callbacks.php +++ b/grade/report/grader/ajax_callbacks.php @@ -35,10 +35,12 @@ if (!$course = $DB->get_record('course', array('id' => $courseid))) { } $context = get_context_instance(CONTEXT_COURSE, $course->id); require_login($course); -confirm_sesskey(); switch ($action) { case 'update': + if (!confirm_sesskey()) { + break; + } require_capability('moodle/grade:edit', $context); if (!empty($userid) && !empty($itemid) && $newvalue !== false && !empty($type)) {