Make WordPress Core


Ignore:
Timestamp:
05/02/2006 10:36:06 PM (20 years ago)
Author:
ryan
Message:

Nonce from above. #2678

File:
1 edited

Legend:

Unmodified
Added
Removed
  • trunk/wp-admin/post.php

    r3721 r3759  
    2525case 'postajaxpost':
    2626case 'post':
    27     check_admin_referer();
     27    check_admin_referer('add-post');
    2828   
    2929    $post_ID = 'post' == $action ? write_post() : edit_post();
     
    7979
    8080case 'editattachment':
    81     check_admin_referer();
     81    $post_id = (int) $_POST['post_ID'];
    8282
    83     $post_id = (int) $_POST['post_ID'];
     83    check_admin_referer('update-attachment' . $post_id);
    8484
    8585    // Don't let these be changed
     
    9797
    9898case 'editpost':
    99     check_admin_referer();
     99    $post_ID = (int) $_POST['post_ID'];
     100    check_admin_referer('update-post' . $post_ID);
    100101   
    101102    $post_ID = edit_post();
     
    122123
    123124case 'delete':
    124     check_admin_referer();
    125 
    126125    $post_id = (isset($_GET['post']))  ? intval($_GET['post']) : intval($_POST['post_ID']);
     126    check_admin_referer('delete-post' . $post_id);
    127127
    128128    $post = & get_post($post_id);
Note: See TracChangeset for help on using the changeset viewer.