Make WordPress Core


Ignore:
Timestamp:
05/02/2006 10:36:06 PM (20 years ago)
Author:
ryan
Message:

Nonce from above. #2678

File:
1 edited

Legend:

Unmodified
Added
Removed
  • trunk/wp-admin/page.php

    r3674 r3759  
    2525switch($action) {
    2626case 'post':
    27 
     27    check_admin_referer('add-page');
    2828    $page_ID = write_post();
    2929
     
    7777case 'editattachment':
    7878    $page_id = $post_ID = (int) $_POST['post_ID'];
     79    check_admin_referer('update-attachment' . $page_id);
    7980
    8081    // Don't let these be changed
     
    9293
    9394case 'editpost':
     95    $page_ID = (int) $_POST['post_ID'];
     96    check_admin_referer('update-page' . $page_ID);
     97
    9498    $page_ID = edit_post();
    9599
     
    115119
    116120case 'delete':
    117     check_admin_referer();
    118 
    119121    $page_id = (isset($_GET['post']))  ? intval($_GET['post']) : intval($_POST['post_ID']);
     122    check_admin_referer('delete-page' .  $page_id);
    120123
    121124    $page = & get_post($page_id);
Note: See TracChangeset for help on using the changeset viewer.