@@ -3030,16 +3030,31 @@ public static function displayBlogsList()
3030
3030
$ visibility_icon = ($ info_log [2 ] == 0 ) ? 'invisible ' : 'visible ' ;
3031
3031
$ visibility_info = ($ info_log [2 ] == 0 ) ? 'Visible ' : 'Invisible ' ;
3032
3032
3033
- $ my_image = '<a href=" ' .api_get_self ().'?action=visibility&blog_id= ' .$ info_log [3 ].'"> ' ;
3033
+ $ secToken = Security::get_existing_token ('blog ' );
3034
+
3035
+ $ my_image = '<a href=" ' .api_get_self ().'? '
3036
+ .http_build_query ([
3037
+ 'action ' => 'visibility ' ,
3038
+ 'blog_id ' => $ info_log [3 ],
3039
+ 'blog_sec_token ' => $ secToken ,
3040
+ ]).'"> ' ;
3034
3041
$ my_image .= Display::return_icon ($ visibility_icon .'.png ' , get_lang ($ visibility_info ));
3035
3042
$ my_image .= "</a> " ;
3036
3043
3037
- $ my_image .= '<a href=" ' .api_get_self ().'?action=edit&blog_id= ' .$ info_log [3 ].'"> ' ;
3044
+ $ my_image .= '<a href=" ' .api_get_self ().'? '
3045
+ .http_build_query ([
3046
+ 'action ' => 'edit ' ,
3047
+ 'blog_id ' => $ info_log [3 ],
3048
+ ]).'"> ' ;
3038
3049
$ my_image .= Display::return_icon ('edit.png ' , get_lang ('EditBlog ' ));
3039
3050
$ my_image .= "</a> " ;
3040
3051
3041
- $ my_image .= '<a href=" ' .api_get_self ().'?action=delete&blog_id= ' .$ info_log [3 ].'" ' ;
3042
- $ my_image .= 'onclick="javascript:if(!confirm( \'' .addslashes (
3052
+ $ my_image .= '<a href=" ' .api_get_self ().'? '
3053
+ .http_build_query ([
3054
+ 'action ' => 'delete ' ,
3055
+ 'blog_id ' => $ info_log [3 ],
3056
+ 'blog_sec_token ' => $ secToken ,
3057
+ ]).'" onclick="javascript:if(!confirm( \'' .addslashes (
3043
3058
api_htmlentities (get_lang ("ConfirmYourChoice " ), ENT_QUOTES , $ charset )
3044
3059
).'\')) return false;" > ' ;
3045
3060
$ my_image .= Display::return_icon ('delete.png ' , get_lang ('DeleteBlog ' ));
0 commit comments