Add tests for parser tag hooks.
[lhc/web/wiklou.git] / includes / HistoryPage.php
index 88a8ee4..fed09ae 100644 (file)
@@ -171,6 +171,7 @@ class HistoryPage {
                        $pager->getBody() .
                        $pager->getNavigationBar()
                );
+               $wgOut->preventClickjacking( $pager->getPreventClickjacking() );
 
                wfProfileOut( __METHOD__ );
        }
@@ -309,6 +310,7 @@ class HistoryPage {
 class HistoryPager extends ReverseChronologicalPager {
        public $lastRow = false, $counter, $historyPage, $title, $buttons, $conds;
        protected $oldIdChecked;
+       protected $preventClickjacking = false;
 
        function __construct( $historyPage, $year = '', $month = '', $tagFilter = '', $conds = array() ) {
                parent::__construct();
@@ -399,6 +401,7 @@ class HistoryPager extends ReverseChronologicalPager {
                ) . "\n";
 
                if ( $wgUser->isAllowed( 'deleterevision' ) ) {
+                       $this->preventClickjacking();
                        $float = $wgContLang->alignEnd();
                        # Note bug #20966, <button> is non-standard in IE<8
                        $element = Html::element( 'button',
@@ -415,6 +418,7 @@ class HistoryPager extends ReverseChronologicalPager {
                        $this->buttons .= $element;
                }
                if ( $wgUser->isAllowed( 'revisionmove' ) ) {
+                       $this->preventClickjacking();
                        $float = $wgContLang->alignEnd();
                        # Note bug #20966, <button> is non-standard in IE<8
                        $element = Html::element( 'button',
@@ -516,6 +520,7 @@ class HistoryPager extends ReverseChronologicalPager {
                $del = '';
                // Show checkboxes for each revision
                if ( $wgUser->isAllowed( 'deleterevision' ) || $wgUser->isAllowed( 'revisionmove' ) ) {
+                       $this->preventClickjacking();
                        // If revision was hidden from sysops, disable the checkbox
                        // However, if the user has revisionmove rights, we cannot disable the checkbox
                        if ( !$rev->userCan( Revision::DELETED_RESTRICTED ) && !$wgUser->isAllowed( 'revisionmove' ) ) {
@@ -565,6 +570,7 @@ class HistoryPager extends ReverseChronologicalPager {
                # Rollback and undo links
                if ( !is_null( $next ) && is_object( $next ) ) {
                        if ( $latest && $this->title->userCan( 'rollback' ) && $this->title->userCan( 'edit' ) ) {
+                               $this->preventClickjacking();
                                $tools[] = '<span class="mw-rollback-link">' .
                                        $this->getSkin()->buildRollbackLink( $rev ) . '</span>';
                        }
@@ -754,6 +760,20 @@ class HistoryPager extends ReverseChronologicalPager {
                        return '';
                }
        }
+
+       /**
+        * This is called if a write operation is possible from the generated HTML
+        */
+       function preventClickjacking( $enable = true ) {
+               $this->preventClickjacking = $enable;
+       }
+
+       /**
+        * Get the "prevent clickjacking" flag
+        */
+       function getPreventClickjacking() {
+               return $this->preventClickjacking;
+       }
 }
 
 /**