Make WordPress Core


Ignore:
Timestamp:
05/02/2006 10:36:06 PM (20 years ago)
Author:
ryan
Message:

Nonce from above. #2678

File:
1 edited

Legend:

Unmodified
Added
Removed
  • trunk/wp-admin/link.php

    r3570 r3759  
    3030switch ($action) {
    3131        case 'deletebookmarks' :
    32         check_admin_referer();
     32        check_admin_referer('bulk-bookmarks');
    3333
    3434        // check the current user's level first.
     
    5454
    5555    case 'move' :
    56         check_admin_referer();
     56        check_admin_referer('bulk-bookmarks');
    5757
    5858        // check the current user's level first.
     
    7373
    7474    case 'add' :
    75         check_admin_referer();
     75        check_admin_referer('add-bookmark');
    7676
    7777        add_link();
     
    8181
    8282    case 'save' :
    83         check_admin_referer();
     83        $link_id = (int) $_POST['link_id'];
     84        check_admin_referer('update-bookmark' . $link_id);
    8485
    85         $link_id = (int) $_POST['link_id'];
    8686        edit_link($link_id);
    8787
     
    9191
    9292    case 'delete' :
    93         check_admin_referer();
     93        $link_id = (int) $_GET['link_id'];
     94        check_admin_referer('delete-bookmark' . $link_id);
    9495
    9596        if (!current_user_can('manage_links'))
    9697            die(__("Cheatin' uh ?"));
    97 
    98         $link_id = (int) $_GET['link_id'];
    9998
    10099        wp_delete_link($link_id);
Note: See TracChangeset for help on using the changeset viewer.