"MDL-13766, remove debug line and added confirm_sesskey to repository_ajax"
authorDongsheng Cai <unoter@gmail.com>
Mon, 28 Jun 2010 02:13:58 +0000 (02:13 +0000)
committerDongsheng Cai <unoter@gmail.com>
Mon, 28 Jun 2010 02:13:58 +0000 (02:13 +0000)
repository/filepicker.js
repository/repository_ajax.php

index 5daa01a..332516b 100644 (file)
@@ -335,7 +335,6 @@ M.core_filepicker.init = function(Y, options) {
                 title.id = 'grid-title-'+client_id+'-'+String(count);
                 title.className = 'label';
                 var filename = node.title;
-                console.info(node);
                 if (node.shorttitle) {
                     filename = node.shorttitle;
                 }
index 0226577..34d7358 100755 (executable)
@@ -59,6 +59,11 @@ header('Expires: Sat, 26 Jul 1997 05:00:00 GMT');
 $err = new stdclass;
 $err->client_id = $client_id;
 
+if (!confirm_sesskey()) {
+    $err->error = get_string('invalidsesskey');
+    die(json_encode($err));
+}
+
 /// Check permissions
 if (! (isloggedin() && repository::check_context($contextid)) ) {
     $err->e = get_string('nopermissiontoaccess', 'repository');