From cacf56f2766a151e96c842860f16b3cf07a3a521 Mon Sep 17 00:00:00 2001 From: real_nowhereman Date: Sun, 10 Feb 2008 14:11:44 +0000 Subject: [PATCH] admin.php allowed to see intro panel to non-loggedin users! (not really harmful, it just looked as if it was) --- admin/main.php | 16 +++++++++------- 1 file changed, 9 insertions(+), 7 deletions(-) diff --git a/admin/main.php b/admin/main.php index ff2d499..795c612 100755 --- a/admin/main.php +++ b/admin/main.php @@ -56,6 +56,14 @@ $fp_admin =& new $panelclass($smarty); } + + /* check if user is loggedin */ + + if (!user_loggedin()) { + utils_redirect("login.php"); + die(); + } + $action = isset($_GET['action'])? $_GET['action'] : 'default'; if (!$fp_admin) @@ -71,13 +79,7 @@ $smarty->assign('panel_url', $panel_url); $smarty->assign('action_url', $action_url); - /* check if user is loggedin */ - - if (!user_loggedin()) { - utils_redirect("login.php"); - die(); - } - + if (!empty($_POST)) check_admin_referer("admin_{$panel}_{$action}");