From 8484ce22584b8714622833adcc7ebfe3ef9cf90e Mon Sep 17 00:00:00 2001 From: Andrew Dolgov Date: Mon, 26 Dec 2011 12:02:52 +0400 Subject: experimental CSRF protection --- classes/article.php | 6 ++++++ classes/feeds.php | 6 ++++++ classes/handler.php | 4 ++++ classes/pref_feeds.php | 7 +++++++ classes/pref_filters.php | 6 ++++++ classes/pref_instances.php | 6 ++++++ classes/pref_labels.php | 6 ++++++ classes/pref_prefs.php | 6 ++++++ classes/pref_users.php | 7 ++++++- classes/rpc.php | 6 ++++++ 10 files changed, 59 insertions(+), 1 deletion(-) (limited to 'classes') diff --git a/classes/article.php b/classes/article.php index 90ca129b9..30f0c7d10 100644 --- a/classes/article.php +++ b/classes/article.php @@ -1,6 +1,12 @@ args = $args; } + function csrf_ignore($method) { + return true; + } + function before() { return true; } diff --git a/classes/pref_feeds.php b/classes/pref_feeds.php index 5df5eb939..b83abd789 100644 --- a/classes/pref_feeds.php +++ b/classes/pref_feeds.php @@ -1,5 +1,12 @@ "; diff --git a/classes/pref_filters.php b/classes/pref_filters.php index d953a8d1d..4ab12410f 100644 --- a/classes/pref_filters.php +++ b/classes/pref_filters.php @@ -1,6 +1,12 @@