mirror of
https://github.com/slawkens/myaac.git
synced 2025-12-01 23:36:50 +01:00
Protect against csrf in more places (accounts & guilds pages)
This commit is contained in:
@@ -28,6 +28,8 @@ if(!$logged) {
|
||||
return;
|
||||
}
|
||||
|
||||
csrfProtect();
|
||||
|
||||
if(Forum::canPost($account_logged)) {
|
||||
$players_from_account = $db->query('SELECT `players`.`name`, `players`.`id` FROM `players` WHERE `players`.`account_id` = '.(int) $account_logged->getId())->fetchAll();
|
||||
$section_id = $_REQUEST['section_id'] ?? null;
|
||||
|
||||
Reference in New Issue
Block a user