diff --git a/event/main_listener.php b/event/main_listener.php index dda6095..6fedbff 100644 --- a/event/main_listener.php +++ b/event/main_listener.php @@ -355,11 +355,17 @@ public function acp_manage_forums_update_data_after($event) // MCP public function mcp_forum_view_before($event) { - $attr_id = (int) $this->request->variable('attr_id', 0); + add_form_key('qte_mcp_attr_apply', '_QTE'); + $attr_id = (int) $this->request->variable('attr_id', 0, false, \phpbb\request\request_interface::POST); $forum_id = (int) $event['forum_info']['forum_id']; if ($attr_id) { + if (!check_form_key('qte_mcp_attr_apply')) + { + trigger_error($this->language->lang('FORM_INVALID')); + } + $this->qte->mcp_attr_apply($attr_id, $forum_id, $event['topic_id_list']); } @@ -635,6 +641,11 @@ public function viewtopic_add_quickmod_option_before($event) if ($attr_id) { + if (!check_link_hash($this->request->variable('hash', ''), 'qte_attr_apply')) + { + return; + } + $this->qte->get_users_by_user_id($this->user->data['user_id']); $this->qte->attr_apply($attr_id, $event['topic_id'], $event['forum_id'], $event['topic_data']['topic_attr_id'], $event['topic_data']['topic_poster'], $event['viewtopic_url']); } diff --git a/qte.php b/qte.php index c7a348b..081eb53 100644 --- a/qte.php +++ b/qte.php @@ -181,7 +181,7 @@ public function attr_select($forum_id, $author_id = 0, $attribute_id = 0, $viewt 'S_SELECTED' => (!empty($attribute_id) && ($attr['attr_id'] == $attribute_id)) ? true : false, 'S_QTE_DESC' => !empty($attr['attr_desc']) ? true : false, - 'U_QTE_URL' => !empty($viewtopic_url) ? append_sid($viewtopic_url, ['attr_id' => $attr['attr_id']]) : false, + 'U_QTE_URL' => !empty($viewtopic_url) ? append_sid($viewtopic_url, ['attr_id' => $attr['attr_id'], 'hash' => generate_link_hash('qte_attr_apply')]) : false, ]); } } @@ -193,7 +193,7 @@ public function attr_select($forum_id, $author_id = 0, $attribute_id = 0, $viewt 'S_QTE_SELECTED' => ($s_delete && ($attribute_id == self::DELETE)) ? true : false, 'S_QTE_KEEP' => !empty($attribute_id) && ($attribute_id == self::KEEP) ? true : false, - 'U_QTE_URL' => !empty($viewtopic_url) ? append_sid($viewtopic_url, ['attr_id' => self::DELETE]) : false, + 'U_QTE_URL' => !empty($viewtopic_url) ? append_sid($viewtopic_url, ['attr_id' => self::DELETE, 'hash' => generate_link_hash('qte_attr_apply')]) : false, ]); } diff --git a/styles/prosilver/template/event/mcp_forum_actions_before.html b/styles/prosilver/template/event/mcp_forum_actions_before.html index 122daaf..9fd2d76 100644 --- a/styles/prosilver/template/event/mcp_forum_actions_before.html +++ b/styles/prosilver/template/event/mcp_forum_actions_before.html @@ -1,4 +1,5 @@ {% if S_QTE_SELECT %} +{{ S_FORM_TOKEN_QTE }}