mirror of
https://gitlab.archlinux.org/archlinux/aurweb.git
synced 2025-02-03 10:43:03 +01:00
Merge branch 'maint'
Conflicts: web/html/account.php web/html/addvote.php web/html/pkgsubmit.php web/lib/acctfuncs.inc.php web/template/actions_form.php web/template/pkg_comment_form.php web/template/pkg_comments.php web/template/pkg_details.php web/template/pkg_search_results.php web/template/tu_details.php
This commit is contained in:
commit
f3ce74c714
15 changed files with 78 additions and 46 deletions
|
@ -19,7 +19,11 @@ if (isset($_COOKIE["AURSID"])) {
|
|||
|
||||
if ($atype == "Trusted User" || $atype == "Developer") {
|
||||
|
||||
if (!empty($_POST['addVote'])) {
|
||||
if (!empty($_POST['addVote']) && !check_token()) {
|
||||
$error = __("Invalid token for user action.");
|
||||
}
|
||||
|
||||
if (!empty($_POST['addVote']) && check_token()) {
|
||||
$error = "";
|
||||
|
||||
if (!empty($_POST['user'])) {
|
||||
|
@ -79,6 +83,7 @@ if ($atype == "Trusted User" || $atype == "Developer") {
|
|||
<b><?php print __("Proposal") ?></b><br />
|
||||
<textarea name="agenda" rows="15" cols="80"><?php if (!empty($_POST['agenda'])) { print htmlentities($_POST['agenda']); } ?></textarea><br />
|
||||
<input type="hidden" name="addVote" value="1" />
|
||||
<input type="hidden" name="token" value="<?php print htmlspecialchars($_COOKIE['AURSID']) ?>" />
|
||||
<input type="submit" class="button" value="<?php print __("Submit"); ?>" />
|
||||
</p>
|
||||
</form>
|
||||
|
|
Loading…
Add table
Add a link
Reference in a new issue