diff options
author | thomascube <thomas@roundcube.net> | 2009-07-21 16:02:33 +0000 |
---|---|---|
committer | thomascube <thomas@roundcube.net> | 2009-07-21 16:02:33 +0000 |
commit | 5499336feff22f682448dd99cc00a9b36701fcd1 (patch) | |
tree | 84c0fcf73be4f5c51f58c9656aaaefecd3530d9d /program/steps/settings/save_identity.inc | |
parent | 61e96cd1f9b32345fd15ae826674f38f0495baa3 (diff) |
Use global request tokens and automatically protect all POST requests
Diffstat (limited to 'program/steps/settings/save_identity.inc')
-rw-r--r-- | program/steps/settings/save_identity.inc | 8 |
1 files changed, 1 insertions, 7 deletions
diff --git a/program/steps/settings/save_identity.inc b/program/steps/settings/save_identity.inc index 86ff263d2..d36114cd0 100644 --- a/program/steps/settings/save_identity.inc +++ b/program/steps/settings/save_identity.inc @@ -5,7 +5,7 @@ | program/steps/settings/save_identity.inc | | | | This file is part of the RoundCube Webmail client | - | Copyright (C) 2005-2007, RoundCube Dev. - Switzerland | + | Copyright (C) 2005-2009, RoundCube Dev. - Switzerland | | Licensed under the GNU GPL | | | | PURPOSE: | @@ -26,12 +26,6 @@ $a_html_cols = array('signature'); $a_boolean_cols = array('standard', 'html_signature'); $updated = $default_id = false; -// check request token -if (!$RCMAIL->check_request('save-identity.'.intval(get_input_value('_iid', RCUBE_INPUT_POST)), RCUBE_INPUT_POST)) { - $OUTPUT->show_message('invalidrequest', 'error'); - rcmail_overwrite_action('identities'); - return; -} // check input if (empty($_POST['_name']) || (empty($_POST['_email']) && IDENTITIES_LEVEL != 1 && IDENTITIES_LEVEL != 3)) { |