* Rewrote showEXIFdata() to use addWikiText() instead of addHTML()
[lhc/web/wiklou.git] / includes / SpecialIpblocklist.php
index 87d9e39..492f78d 100644 (file)
@@ -6,7 +6,7 @@
  */
 
 /**
- *
+ * @todo document
  */
 function wfSpecialIpblocklist() {
        global $wgUser, $wgOut, $wgRequest;
@@ -20,8 +20,9 @@ function wfSpecialIpblocklist() {
        if ( "success" == $action ) {
                $msg = wfMsg( "ipusuccess", htmlspecialchars( $ip ) );
                $ipu->showList( $msg );
-       } else if ( "submit" == $action && $wgRequest->wasPosted() ) {
-               if ( ! $wgUser->isSysop() ) {
+       } else if ( "submit" == $action && $wgRequest->wasPosted() &&
+               $wgUser->matchEditToken( $wgRequest->getVal( 'wpEditToken' ) ) ) {
+               if ( ! $wgUser->isAllowed('block') ) {
                        $wgOut->sysopRequired();
                        return;
                }
@@ -63,6 +64,7 @@ class IPUnblockForm {
                        $wgOut->setSubtitle( wfMsg( "formerror" ) );
                        $wgOut->addHTML( "<p class='error'>{$err}</p>\n" );
                }
+               $token = htmlspecialchars( $wgUser->editToken() );
                
                $wgOut->addHTML( "
 <form id=\"unblockip\" method=\"post\" action=\"{$action}\">
@@ -86,6 +88,7 @@ class IPUnblockForm {
                        </td>
                </tr>
        </table>
+       <input type='hidden' name='wpEditToken' value=\"{$token}\" />
 </form>\n" );
 
        }
@@ -141,7 +144,7 @@ function wfAddRow( $block, $tag ) {
        $addr = $block->mAuto ? "#{$block->mId}" : $block->mAddress;
 
        $name = User::whoIs( $block->mBy );
-       $ulink = $sk->makeKnownLink( $wgContLang->getNsText( Namespace::getUser() ). ":{$name}", $name );
+       $ulink = $sk->makeKnownLinkObj( Title::makeTitle( NS_USER, $name ), $name );
        $formattedTime = $wgLang->timeanddate( $block->mTimestamp, true );
        
        if ( $block->mExpiry === "" ) {
@@ -161,17 +164,14 @@ function wfAddRow( $block, $tag ) {
                $wgOut->addHTML( " ({$clink})" );
        }
 
-       if ( $wgUser->isSysop() ) {
+       if ( $wgUser->isAllowed('block') ) {
                $titleObj = Title::makeTitle( NS_SPECIAL, "Ipblocklist" );
                $ublink = "<a href=\"" . 
                  $titleObj->escapeLocalURL( "action=unblock&ip=" . urlencode( $addr ) ) . "\">" .
                  wfMsg( "unblocklink" ) . "</a>";
                $wgOut->addHTML( " ({$ublink})" );
        }
-       if ( "" != $block->mReason ) {
-               $wgOut->addHTML( " <em>(" . htmlspecialchars( $block->mReason ) .
-                 ")</em>" );
-       }
+       $wgOut->addHTML( $sk->commentBlock( $block->mReason ) );
        $wgOut->addHTML( "</li>\n" );
 }