mirror of
https://github.com/Pathduck/gallery3.git
synced 2026-05-21 11:59:13 -04:00
Controller auth / CSRF fixes
This commit is contained in:
@@ -45,9 +45,13 @@ class Organize_Controller extends Controller {
|
||||
access::verify_csrf();
|
||||
|
||||
$target_album = ORM::factory("item", $target_album_id);
|
||||
access::required("view", $target_album);
|
||||
access::required("add", $target_album);
|
||||
|
||||
foreach ($this->input->post("source_ids") as $source_id) {
|
||||
$source = ORM::factory("item", $source_id);
|
||||
if (!$source->contains($target_album)) {
|
||||
access::required("edit", $source);
|
||||
item::move($source, $target_album);
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user