From 9d90b9980e33f8f6bb2e54b0fb33ee8026a8defc Mon Sep 17 00:00:00 2001 From: Nicolas Connault Date: Thu, 29 Oct 2009 09:01:58 +0000 Subject: [PATCH] MDL-20663 (Correctly) added sesskey confirmation --- grade/report/grader/ajax_callbacks.php | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/grade/report/grader/ajax_callbacks.php b/grade/report/grader/ajax_callbacks.php index 0c7ae059a4..a1ef4445e3 100644 --- a/grade/report/grader/ajax_callbacks.php +++ b/grade/report/grader/ajax_callbacks.php @@ -35,10 +35,12 @@ if (!$course = $DB->get_record('course', array('id' => $courseid))) { } $context = get_context_instance(CONTEXT_COURSE, $course->id); require_login($course); -confirm_sesskey(); switch ($action) { case 'update': + if (!confirm_sesskey()) { + break; + } require_capability('moodle/grade:edit', $context); if (!empty($userid) && !empty($itemid) && $newvalue !== false && !empty($type)) { -- 2.39.5