Changeset 8024

Show
Ignore:
Timestamp:
05/30/08 20:43:42 (3 months ago)
Author:
ryan
Message:

Add some noncing. Props andy.

Files:

Legend:

Unmodified
Added
Removed
Modified
Copied
Moved
  • branches/2.5/wp-admin/async-upload.php

    r8022 r8024  
    2727} 
    2828 
     29check_admin_referer('media-form'); 
     30 
    2931$id = media_handle_upload('async-upload', $_REQUEST['post_id']); 
    3032if (is_wp_error($id)) { 
  • branches/2.5/wp-admin/includes/media.php

    r7963 r8024  
    792792                "post_id" : "<?php echo $post_id; ?>", 
    793793                "auth_cookie" : "<?php echo $_COOKIE[AUTH_COOKIE]; ?>", 
     794                "_wpnonce" : "<?php echo wp_create_nonce('media-form'); ?>", 
    794795                "type" : "<?php echo $type; ?>", 
    795796                "tab" : "<?php echo $tab; ?>",