X-Git-Url: https://git.mxchange.org/?a=blobdiff_plain;f=actions%2Fsmssettings.php;h=5db26730a50b1c5f05ccb314dc4dab33c3adba7b;hb=661202be3e28eeffeacb8cbfbec88a7352bcce55;hp=b5d55658f3b9b4f201836d3eaceeaacc5534b372;hpb=76f6e04a45eb7ae7ec73f83cda912b69bb0e4ac9;p=quix0rs-gnu-social.git diff --git a/actions/smssettings.php b/actions/smssettings.php index b5d55658f3..5db26730a5 100644 --- a/actions/smssettings.php +++ b/actions/smssettings.php @@ -35,7 +35,7 @@ class SmssettingsAction extends EmailsettingsAction { 'id' => 'smssettings', 'action' => common_local_url('smssettings'))); - + common_hidden('token', common_session_token()); common_element('h2', NULL, _('Address')); if ($user->sms) { @@ -56,8 +56,8 @@ class SmssettingsAction extends EmailsettingsAction { common_element('span', 'address unconfirmed', $confirm->address . ' (' . $carrier->name . ')'); common_element('span', 'input_instructions', _('Awaiting confirmation on this phone number.')); - common_hidden('sms', $user->sms); - common_hidden('carrier', $user->carrier); + common_hidden('sms', $confirm->address); + common_hidden('carrier', $confirm->address_extra); common_element_end('p'); common_submit('cancel', _('Cancel')); common_input('code', _('Confirmation code'), NULL, @@ -117,6 +117,14 @@ class SmssettingsAction extends EmailsettingsAction { function handle_post() { + # CSRF protection + + $token = $this->trimmed('token'); + if (!$token || $token != common_session_token()) { + $this->show_form(_('There was a problem with your session token. Try again, please.')); + return; + } + if ($this->arg('save')) { $this->save_preferences(); } else if ($this->arg('add')) {