From 865ecc87963dc3b26e66296616eef2a1cc41ac3f Mon Sep 17 00:00:00 2001 From: Andrew Dolgov Date: Wed, 25 Oct 2023 12:55:09 +0300 Subject: move to psr-4 autoloader --- classes/PluginHandler.php | 29 +++++++++++++++++++++++++++++ 1 file changed, 29 insertions(+) create mode 100644 classes/PluginHandler.php (limited to 'classes/PluginHandler.php') diff --git a/classes/PluginHandler.php b/classes/PluginHandler.php new file mode 100644 index 000000000..a6f0a4965 --- /dev/null +++ b/classes/PluginHandler.php @@ -0,0 +1,29 @@ +get_plugin($plugin_name); + $csrf_token = ($_POST["csrf_token"] ?? ""); + + if ($plugin) { + if (method_exists($plugin, $method)) { + if (validate_csrf($csrf_token) || $plugin->csrf_ignore($method)) { + $plugin->$method(); + } else { + user_error("Rejected {$plugin_name}->{$method}(): invalid CSRF token.", E_USER_WARNING); + print Errors::to_json(Errors::E_UNAUTHORIZED); + } + } else { + user_error("Rejected {$plugin_name}->{$method}(): unknown method.", E_USER_WARNING); + print Errors::to_json(Errors::E_UNKNOWN_METHOD); + } + } else { + user_error("Rejected {$plugin_name}->{$method}(): unknown plugin.", E_USER_WARNING); + print Errors::to_json(Errors::E_UNKNOWN_PLUGIN); + } + } +} -- cgit v1.2.3