admin skips input validation

This commit is contained in:
real_nowhereman 2008-03-19 13:46:29 +00:00
parent e61031f5b2
commit e61df38f90

View File

@ -89,48 +89,57 @@
$errors = array(); $errors = array();
/* $loggedin = false;
* check name
*
*/
if (!$name) { if (user_loggedin()) {
$errors['name'] = $lerr['name']; $loggedin = $arr['loggedin']=true;
} } else {
/*
* check name
*
*/
/* if (!$name) {
* check email $errors['name'] = $lerr['name'];
*
*/
if ($email) {
$_is_valid = !(preg_match('!@.*@|\.\.|\,|\;!', $email) ||
!preg_match('!^.+\@(\[?)[a-zA-Z0-9\.\-]+\.([a-zA-Z]{2,4}|[0-9]{1,3})(\]?)$!', $email));
if (!$_is_valid) {
$errors['email'] = $lerr['email'];
} }
}
/* /*
* check url * check email
* *
*/ */
if ($email) {
$_is_valid = !(preg_match('!@.*@|\.\.|\,|\;!', $email) ||
!preg_match('!^.+\@(\[?)[a-zA-Z0-9\.\-]+\.([a-zA-Z]{2,4}|[0-9]{1,3})(\]?)$!', $email));
if (!$_is_valid) {
$errors['email'] = $lerr['email'];
}
if ($url) {
if (!preg_match('!^http(s)?://[\w-]+\.[\w-]+(\S+)?$!i', $url)) {
// || preg_match('!^http(s)?://localhost!', $value);
$errors['url'] = $lerr['www'];
} }
}
/*
* check url
*
*/
if ($url) {
if (!preg_match('!^http(s)?://[\w-]+\.[\w-]+(\S+)?$!i', $url)) {
// || preg_match('!^http(s)?://localhost!', $value);
$errors['url'] = $lerr['www'];
}
}
}
if (!$content) { if (!$content) {
$errors['content'] = $lerr['comment']; $errors['content'] = $lerr['comment'];
} }
if ($errors) { if ($errors) {
$smarty->assign('error', $errors); $smarty->assign('error', $errors);
return false; return false;
@ -139,11 +148,6 @@
$arr['version'] = system_ver(); $arr['version'] = system_ver();
$arr['name'] = $_POST['name']; $arr['name'] = $_POST['name'];
$loggedin = false;
if (user_loggedin()) {
$loggedin = $arr['loggedin']=true;
}
if (!$loggedin) if (!$loggedin)
setcookie('comment_author_' . COOKIEHASH, setcookie('comment_author_' . COOKIEHASH,