From dfc133c09b1c8ee5f82b5bce5a5632058a8e38e7 Mon Sep 17 00:00:00 2001 From: Tim Hunt Date: Mon, 2 Nov 2009 17:01:02 +0000 Subject: [PATCH] lesson: MDL-20705 Fix XSRF issues. Uses new require_sesskey funciton from MDL-20702. --- mod/lesson/action/addcluster.php | 2 +- mod/lesson/action/addendofbranch.php | 2 +- mod/lesson/action/addendofcluster.php | 2 +- mod/lesson/action/confirmdelete.php | 2 +- mod/lesson/action/continue.php | 2 +- mod/lesson/action/delete.php | 2 +- mod/lesson/action/insertpage.php | 2 +- mod/lesson/action/moveit.php | 2 +- mod/lesson/action/updatepage.php | 2 +- mod/lesson/essay.php | 4 ++-- 10 files changed, 11 insertions(+), 11 deletions(-) diff --git a/mod/lesson/action/addcluster.php b/mod/lesson/action/addcluster.php index 0e34c1485d..8a3a709092 100644 --- a/mod/lesson/action/addcluster.php +++ b/mod/lesson/action/addcluster.php @@ -5,7 +5,7 @@ * @license http://www.gnu.org/copyleft/gpl.html GNU Public License * @package lesson **/ - confirm_sesskey(); + require_sesskey(); // first get the preceeding page // if $pageid = 0, then we are inserting a new page at the beginning of the lesson diff --git a/mod/lesson/action/addendofbranch.php b/mod/lesson/action/addendofbranch.php index c47fb157bf..b6bb3be4c0 100644 --- a/mod/lesson/action/addendofbranch.php +++ b/mod/lesson/action/addendofbranch.php @@ -5,7 +5,7 @@ * @license http://www.gnu.org/copyleft/gpl.html GNU Public License * @package lesson **/ - confirm_sesskey(); + require_sesskey(); // first get the preceeding page $pageid = required_param('pageid', PARAM_INT); diff --git a/mod/lesson/action/addendofcluster.php b/mod/lesson/action/addendofcluster.php index eef19b3eca..41509501cd 100644 --- a/mod/lesson/action/addendofcluster.php +++ b/mod/lesson/action/addendofcluster.php @@ -5,7 +5,7 @@ * @license http://www.gnu.org/copyleft/gpl.html GNU Public License * @package lesson **/ - confirm_sesskey(); + require_sesskey(); // first get the preceeding page $pageid = required_param('pageid', PARAM_INT); diff --git a/mod/lesson/action/confirmdelete.php b/mod/lesson/action/confirmdelete.php index 2b903f1a22..8daa9fee05 100644 --- a/mod/lesson/action/confirmdelete.php +++ b/mod/lesson/action/confirmdelete.php @@ -5,7 +5,7 @@ * @license http://www.gnu.org/copyleft/gpl.html GNU Public License * @package lesson **/ - confirm_sesskey(); + require_sesskey(); $pageid = required_param('pageid', PARAM_INT); if (!$thispage = $DB->get_record("lesson_pages", array ("id" => $pageid))) { diff --git a/mod/lesson/action/continue.php b/mod/lesson/action/continue.php index 93ed99d46c..f14f267bef 100644 --- a/mod/lesson/action/continue.php +++ b/mod/lesson/action/continue.php @@ -5,7 +5,7 @@ * @license http://www.gnu.org/copyleft/gpl.html GNU Public License * @package lesson **/ - confirm_sesskey(); + require_sesskey(); // left menu code // check to see if the user can see the left menu diff --git a/mod/lesson/action/delete.php b/mod/lesson/action/delete.php index 45b875da49..2ba5c4d1c7 100644 --- a/mod/lesson/action/delete.php +++ b/mod/lesson/action/delete.php @@ -5,7 +5,7 @@ * @license http://www.gnu.org/copyleft/gpl.html GNU Public License * @package lesson **/ - confirm_sesskey(); + require_sesskey(); $pageid = required_param('pageid', PARAM_INT); if (!$thispage = $DB->get_record("lesson_pages", array("id" => $pageid))) { diff --git a/mod/lesson/action/insertpage.php b/mod/lesson/action/insertpage.php index c955d2c851..6fa694ebed 100644 --- a/mod/lesson/action/insertpage.php +++ b/mod/lesson/action/insertpage.php @@ -5,7 +5,7 @@ * @license http://www.gnu.org/copyleft/gpl.html GNU Public License * @package lesson **/ - confirm_sesskey(); + require_sesskey(); // check to see if the cancel button was pushed if (optional_param('cancel', '', PARAM_ALPHA)) { diff --git a/mod/lesson/action/moveit.php b/mod/lesson/action/moveit.php index 4a8d4e9085..1c81fe7d97 100644 --- a/mod/lesson/action/moveit.php +++ b/mod/lesson/action/moveit.php @@ -5,7 +5,7 @@ * @license http://www.gnu.org/copyleft/gpl.html GNU Public License * @package lesson **/ - confirm_sesskey(); + require_sesskey(); $pageid = required_param('pageid', PARAM_INT); // page to move if (!$page = $DB->get_record("lesson_pages", array("id" => $pageid))) { diff --git a/mod/lesson/action/updatepage.php b/mod/lesson/action/updatepage.php index b40e2a3f72..55780bb0c3 100644 --- a/mod/lesson/action/updatepage.php +++ b/mod/lesson/action/updatepage.php @@ -5,7 +5,7 @@ * @license http://www.gnu.org/copyleft/gpl.html GNU Public License * @package lesson **/ - confirm_sesskey(); + require_sesskey(); $redirect = optional_param('redirect', '', PARAM_ALPHA); diff --git a/mod/lesson/essay.php b/mod/lesson/essay.php index 4fcf64fe23..45629aeccd 100644 --- a/mod/lesson/essay.php +++ b/mod/lesson/essay.php @@ -70,7 +70,7 @@ } break; case 'grade': // Grading form - get the necessary data - confirm_sesskey(); + require_sesskey(); $attemptid = required_param('attemptid', PARAM_INT); @@ -142,7 +142,7 @@ } break; case 'email': // Sending an email(s) to a single user or all - confirm_sesskey(); + require_sesskey(); // Get our users (could be singular) if ($userid = optional_param('userid', 0, PARAM_INT)) { -- 2.39.5