]> git.mxchange.org Git - quix0rs-gnu-social.git/commitdiff
add csrf protection to profile settings
authorEvan Prodromou <evan@prodromou.name>
Fri, 29 Aug 2008 04:39:09 +0000 (00:39 -0400)
committerEvan Prodromou <evan@prodromou.name>
Fri, 29 Aug 2008 04:39:09 +0000 (00:39 -0400)
darcs-hash:20080829043909-84dde-c70a633c93ab89560bc300817bda66eebf6176cf.gz

actions/profilesettings.php

index bc4fce50b98c2fca8323e0d015c416a0750d08e9..14c725ff91364ea4f87abcf9cc20301b431e6636 100644 (file)
@@ -37,6 +37,7 @@ class ProfilesettingsAction extends SettingsAction {
                                                                                   'id' => 'profilesettings',
                                                                                   'action' =>
                                                                                   common_local_url('profilesettings')));
+               common_hidden('token', common_session_token());
                # too much common patterns here... abstractable?
                common_input('nickname', _('Nickname'),
                                         ($this->arg('nickname')) ? $this->arg('nickname') : $profile->nickname,
@@ -80,6 +81,14 @@ class ProfilesettingsAction extends SettingsAction {
                $language = $this->trimmed('language');
                $timezone = $this->trimmed('timezone');
 
+               # CSRF protection
+
+               $token = $this->trimmed('token');
+               if (!$token || $token != common_session_token()) {
+                       $this->show_form(_('There was a problem with your session token. Try again, please.'));
+                       return;
+               }
+
                # Some validation
 
                if (!Validate::string($nickname, array('min_length' => 1,
@@ -147,9 +156,9 @@ class ProfilesettingsAction extends SettingsAction {
                }
 
                # XXX: XOR
-               
+
                if ($user->autosubscribe ^ $autosubscribe) {
-                       
+
                        $original = clone($user);
 
                        $user->autosubscribe = $autosubscribe;
@@ -162,7 +171,7 @@ class ProfilesettingsAction extends SettingsAction {
                                return;
                        }
                }
-               
+
                $profile = $user->getProfile();
 
                $orig_profile = clone($profile);