Changeset 2845 in subversion
- Timestamp:
- Aug 7, 2009 11:37:15 AM (4 years ago)
- File:
-
- 1 edited
-
trunk/roundcubemail/index.php (modified) (2 diffs)
Legend:
- Unmodified
- Added
- Removed
-
trunk/roundcubemail/index.php
r2840 r2845 143 143 } 144 144 145 // don't check for valid request tokens in these actions 146 $request_check_whitelist = array('login'=>1, 'spell'=>1); 145 147 146 148 // check client X-header to verify request origin … … 152 154 } 153 155 // check request token in POST form submissions 154 else if (!empty($_POST) && $RCMAIL->action != 'login'&& !$RCMAIL->check_request()) {156 else if (!empty($_POST) && !$request_check_whitelist[$RCMAIL->action] && !$RCMAIL->check_request()) { 155 157 $OUTPUT->show_message('invalidrequest', 'error'); 156 158 $OUTPUT->send($RCMAIL->task);
Note: See TracChangeset
for help on using the changeset viewer.
