oops
[lhc/web/wiklou.git] / includes / SpecialEmailuser.php
index 92b938e..577a8e9 100644 (file)
@@ -18,7 +18,7 @@ function wfSpecialEmailuser( $par ) {
                return;
        }
        
-       if ( 0 == $wgUser->getID() ||
+       if ( $wgUser->isAnon() ||
                ( !$wgUser->isValidEmailAddr( $wgUser->getEmail() ) ) ) {
                $wgOut->errorpage( "mailnologin", "mailnologintext" );
                return;
@@ -57,9 +57,14 @@ function wfSpecialEmailuser( $par ) {
 
        $f = new EmailUserForm( $nu->getName() . " <{$address}>", $target );
 
-       if ( "success" == $action ) { $f->showSuccess(); }
-       else if ( "submit" == $action && $wgRequest->wasPosted() ) { $f->doSubmit(); }
-       else { $f->showForm(); }
+       if ( "success" == $action ) {
+               $f->showSuccess();
+       } else if ( "submit" == $action && $wgRequest->wasPosted() &&
+               $wgUser->matchEditToken( $wgRequest->getVal( 'wpEditToken' ) ) ) {
+               $f->doSubmit();
+       } else {
+               $f->showForm();
+       }
 }
 
 /**
@@ -103,6 +108,7 @@ class EmailUserForm {
                $titleObj = Title::makeTitle( NS_SPECIAL, "Emailuser" );
                $action = $titleObj->escapeLocalURL( "target=" .
                        urlencode( $this->target ) . "&action=submit" );
+               $token = $wgUser->editToken();
 
                $wgOut->addHTML( "
 <form id=\"emailuser\" method=\"post\" action=\"{$action}\">
@@ -126,6 +132,7 @@ class EmailUserForm {
 <td>&nbsp;</td><td align='left'>
 <input type='submit' name=\"wpSend\" value=\"{$ems}\" />
 </td></tr></table>
+<input type='hidden' name='wpEditToken' value=\"$token\" />
 </form>\n" );
 
        }
@@ -136,7 +143,7 @@ class EmailUserForm {
                $from = wfQuotedPrintable( $wgUser->getName() ) . " <" . $wgUser->getEmail() . ">";
                $subject = wfQuotedPrintable( $this->subject );
                
-               if (wfRunHooks('EmailUser', $this->mAddress, $from, $subject, $this->text)) {
+               if (wfRunHooks('EmailUser', array(&$this->mAddress, &$from, &$subject, &$this->text))) {
                        
                        $mailResult = userMailer( $this->mAddress, $from, $subject, $this->text );
                        
@@ -144,7 +151,7 @@ class EmailUserForm {
                                $titleObj = Title::makeTitle( NS_SPECIAL, "Emailuser" );
                                $encTarget = wfUrlencode( $this->target );
                                $wgOut->redirect( $titleObj->getFullURL( "target={$encTarget}&action=success" ) );
-                               wfRunHooks('EmailUserComplete', $this->mAddress, $from, $subject, $this->text);
+                               wfRunHooks('EmailUserComplete', array($this->mAddress, $from, $subject, $this->text));
                        } else {
                          $wgOut->addHTML( wfMsg( "usermailererror" ) . $mailResult);
                        }