Todo: protection faille CSRF !!!

This commit is contained in:
Regis Houssin 2009-05-15 10:27:38 +00:00
parent c75a724693
commit 0bd1156782

View File

@ -30,9 +30,12 @@ require_once(DOL_DOCUMENT_ROOT."/lib/admin.lib.php");
$langs->load("admin");
if (!$user->admin)
//Todo protection faille CSRF !!!
if (!eregi(DOL_MAIN_URL_ROOT, $_SERVER['HTTP_REFERER']))
accessforbidden();
if (!$user->admin)
accessforbidden();
$typeconst=array('yesno','texte','chaine');