diff options
author | Cash Costello <cash.costello@gmail.com> | 2009-10-05 23:20:10 +0000 |
---|---|---|
committer | Cash Costello <cash.costello@gmail.com> | 2009-10-05 23:20:10 +0000 |
commit | 39060653573bf4dd51e891aecdb571c78a866675 (patch) | |
tree | f1fc85cba89454a2eeb588a1f85f7dc49f200c5a /views/default/tidypics/image_menu.php | |
parent | 9b3cba566de0bc5740e48f3f50eb8b09ffad49dc (diff) | |
download | elgg-39060653573bf4dd51e891aecdb571c78a866675.tar.gz elgg-39060653573bf4dd51e891aecdb571c78a866675.tar.bz2 |
not using action token validation for image download
Diffstat (limited to 'views/default/tidypics/image_menu.php')
-rw-r--r-- | views/default/tidypics/image_menu.php | 5 |
1 files changed, 1 insertions, 4 deletions
diff --git a/views/default/tidypics/image_menu.php b/views/default/tidypics/image_menu.php index cb004395e..299f4b026 100644 --- a/views/default/tidypics/image_menu.php +++ b/views/default/tidypics/image_menu.php @@ -43,10 +43,7 @@ }
if (get_plugin_setting('download_link', 'tidypics') != "disabled") {
- $ts = time();
- $token = generate_action_token($ts);
-
- $download_url = $vars['url'] . "action/tidypics/download?file_guid=" . $image_guid . "&__elgg_token={$token}&__elgg_ts={$ts}";
+ $download_url = $vars['url'] . "action/tidypics/download?file_guid=" . $image_guid;
?>
<li id="download_image"><a href="<?php echo $download_url; ?>"><?php echo elgg_echo("image:download"); ?></a></li>
<?php
|