Security measures (#1113)

This commit is contained in:
Roman Kelesidis 2023-11-18 10:36:16 +07:00 committed by GitHub
commit 73b07f2e92
No known key found for this signature in database
GPG key ID: 4AEE18F83AFDEB23
2 changed files with 20 additions and 8 deletions

View file

@ -579,6 +579,8 @@ if ($userdata['user_level'] == GROUP_MEMBER || IS_AM) {
} }
} }
// Assign posting title & hidden fields
$page_title = '';
$hidden_form_fields = '<input type="hidden" name="mode" value="' . $mode . '" />'; $hidden_form_fields = '<input type="hidden" name="mode" value="' . $mode . '" />';
switch ($mode) { switch ($mode) {

View file

@ -1097,14 +1097,24 @@ if ($mode == 'read') {
$template->assign_block_vars('switch_privmsg', []); $template->assign_block_vars('switch_privmsg', []);
$template->assign_var('POSTING_USERNAME'); $template->assign_var('POSTING_USERNAME');
$post_a = '&nbsp;'; //
if ($mode == 'post') { // Assign posting title & hidden fields
//
$post_a = false;
switch ($mode) {
case 'post':
$post_a = $lang['SEND_A_NEW_MESSAGE']; $post_a = $lang['SEND_A_NEW_MESSAGE'];
} elseif ($mode == 'reply') { break;
case 'reply':
$post_a = $lang['SEND_A_REPLY']; $post_a = $lang['SEND_A_REPLY'];
$mode = 'post'; $mode = 'post';
} elseif ($mode == 'edit') { break;
case 'edit':
$post_a = $lang['EDIT_MESSAGE']; $post_a = $lang['EDIT_MESSAGE'];
break;
default:
pm_die($lang['NONE_SELECTED']);
break;
} }
$s_hidden_fields = '<input type="hidden" name="folder" value="' . $folder . '" />'; $s_hidden_fields = '<input type="hidden" name="folder" value="' . $folder . '" />';