diff options
author | brettp <brettp@36083f99-b078-4883-b0ff-0f9b5a30f544> | 2010-01-21 01:30:09 +0000 |
---|---|---|
committer | brettp <brettp@36083f99-b078-4883-b0ff-0f9b5a30f544> | 2010-01-21 01:30:09 +0000 |
commit | 0c5b4c242b0805c55ca3b1a887eb222844a66400 (patch) | |
tree | f3455e9dcac50226d33ab3048a691f90ee82d5c5 /views/default/canvas/layouts | |
parent | 3d9fb93c8c91e45b88dfeb816960049e0cb33231 (diff) | |
download | elgg-0c5b4c242b0805c55ca3b1a887eb222844a66400.tar.gz elgg-0c5b4c242b0805c55ca3b1a887eb222844a66400.tar.bz2 |
Fixes #750: All actions require __elgg_ts and __elgg_token.
git-svn-id: http://code.elgg.org/elgg/trunk@3821 36083f99-b078-4883-b0ff-0f9b5a30f544
Diffstat (limited to 'views/default/canvas/layouts')
-rw-r--r-- | views/default/canvas/layouts/widgets.php | 10 |
1 files changed, 9 insertions, 1 deletions
diff --git a/views/default/canvas/layouts/widgets.php b/views/default/canvas/layouts/widgets.php index f6c9dec79..6b89d5435 100644 --- a/views/default/canvas/layouts/widgets.php +++ b/views/default/canvas/layouts/widgets.php @@ -235,6 +235,14 @@ if (is_array($widgettypes) && sizeof($widgettypes) > 0 && $owner && $owner->canE <input type="hidden" name="context" value="<?php echo get_context(); ?>" /> <input type="hidden" name="owner" value="<?php echo page_owner(); ?>" /> + +<?php +$ts = time(); +$token = generate_action_token($ts); +?> +<input type="hidden" name="__elgg_ts" value="<?php echo $ts; ?>" /> +<input type="hidden" name="__elgg_token" value="<?php echo $token; ?>" /> + <input type="submit" value="<?php echo elgg_echo('save'); ?>" class="submit_button" onclick="$('a.toggle_customise_edit_panel').click();" /> <input type="button" value="<?php echo elgg_echo('cancel'); ?>" class="cancel_button" onclick="$('a.toggle_customise_edit_panel').click();" /> @@ -315,4 +323,4 @@ if (is_array($widgettypes) && sizeof($widgettypes) > 0 && $owner && $owner->canE </td> </tr> -</table>
\ No newline at end of file +</table> |