Fix terms and conditions edition (security token was not updated) - refs CT#7909

1.10.x
Yannick Warnier 9 years ago
parent a9f04a946e
commit 219bd6cf0d
  1. 49
      main/admin/legal_add.php

@ -16,8 +16,13 @@ api_protect_admin_script();
// Create the form
$form = new FormValidator('addlegal');
$defaults=array();
if( $form->validate()) {
$defaults = array();
$term_preview = array(
'type' => 0,
'content' => '',
'changes' => '',
);
if ($form->validate()) {
$check = Security::check_token('post');
if ($check) {
$values = $form->getSubmitValues();
@ -25,9 +30,21 @@ if( $form->validate()) {
//language id
$lang = api_get_language_id($lang);
if (isset($values['type'])) {
$type = $values['type'];
} else {
$type = 0;
}
if (isset($values['content'])) {
$content = $values['content'];
} else {
$content = '';
}
if (isset($values['changes'])) {
$changes = $values['changes'];
} else {
$changes = '';
}
$navigator_info = api_get_navigator();
if ($navigator_info['name']=='Internet Explorer' && $navigator_info['version']=='6') {
@ -42,25 +59,26 @@ if( $form->validate()) {
$submit = $values['send'];
}
$default['content']=$content;
$default['content'] = $content;
if (isset($values['language'])) {
if($submit=='back') {
if ($submit == 'back') {
header('Location: legal_add.php');
exit;
} elseif($submit=='save') {
$insert_result = LegalManager::add($lang,$content,$type,$changes);
if ($insert_result )
} elseif ($submit == 'save') {
$insert_result = LegalManager::add($lang, $content, $type, $changes);
if ($insert_result ) {
$message = get_lang('TermAndConditionSaved');
else
} else {
$message = get_lang('TermAndConditionNotSaved');
}
Security::clear_token();
$tok = Security::get_token();
header('Location: legal_list.php?action=show_message&message='.urlencode($message).'&sec_token='.$tok);
exit();
} elseif($submit=='preview') {
$defaults['type']=$type;
$defaults['content']=$content;
$defaults['changes']=$changes;
} elseif ($submit=='preview') {
$defaults['type'] = $type;
$defaults['content'] = $content;
$defaults['changes'] = $changes;
$term_preview = $defaults;
$term_preview['type'] = intval($_POST['type']);
} else {
@ -83,15 +101,16 @@ if( $form->validate()) {
}
}
$form->setDefaults($default);
$form->setDefaults($defaults);
if(isset($_POST['send'])) {
if (isset($_POST['send'])) {
Security::clear_token();
}
$token = Security::get_token();
$form->addElement('hidden','sec_token');
$form->setConstants(array('sec_token' => $token));
//$form->setConstants(array('sec_token' => $token));
$defaults['sec_token'] = $token;
$form->addElement('header', get_lang('DisplayTermsConditions'));
if (isset($_POST['language'])) {

Loading…
Cancel
Save