Cleanup
[lhc/web/wiklou.git] / includes / SpecialUnlockdb.php
index fa674d7..74b794d 100644 (file)
@@ -1,8 +1,7 @@
 <?php
 /**
  *
- * @package MediaWiki
- * @subpackage SpecialPage
+ * @addtogroup SpecialPage
  */
 
 /**
 function wfSpecialUnlockdb() {
        global $wgUser, $wgOut, $wgRequest;
 
-       if ( ! $wgUser->isAllowed('siteadmin') ) {
-               $wgOut->developerRequired();
+       if( !$wgUser->isAllowed( 'siteadmin' ) ) {
+               $wgOut->permissionRequired( 'siteadmin' );
                return;
        }
+
        $action = $wgRequest->getVal( 'action' );
        $f = new DBUnlockForm();
 
-       if ( "success" == $action ) { $f->showSuccess(); }
-       else if ( "submit" == $action && $wgRequest->wasPosted() ) { $f->doSubmit(); }
-       else { $f->showForm( "" ); }
+       if ( "success" == $action ) {
+               $f->showSuccess();
+       } else if ( "submit" == $action && $wgRequest->wasPosted() &&
+               $wgUser->matchEditToken( $wgRequest->getVal( 'wpEditToken' ) ) ) {
+               $f->doSubmit();
+       } else {
+               $f->showForm( "" );
+       }
 }
 
 /**
  *
- * @package MediaWiki
- * @subpackage SpecialPage
+ * @addtogroup SpecialPage
  */
 class DBUnlockForm {
        function showForm( $err )
        {
-               global $wgOut, $wgUser, $wgLang;
+               global $wgOut, $wgUser;
+
+               global $wgReadOnlyFile;
+               if( !file_exists( $wgReadOnlyFile ) ) {
+                       $wgOut->addWikiMsg( 'databasenotlocked' );
+                       return;
+               }
 
                $wgOut->setPagetitle( wfMsg( "unlockdb" ) );
-               $wgOut->addWikiText( wfMsg( "unlockdbtext" ) );
+               $wgOut->addWikiMsg( "unlockdbtext" );
 
                if ( "" != $err ) {
                        $wgOut->setSubtitle( wfMsg( "formerror" ) );
-                       $wgOut->addHTML( "<p><font color='red' size='+1'>{$err}</font>\n" );
+                       $wgOut->addHTML( '<p class="error">' . htmlspecialchars( $err ) . "</p>\n" );
                }
-               $lc = wfMsg( "unlockconfirm" );
-               $lb = wfMsg( "unlockbtn" );
-               $titleObj = Title::makeTitle( NS_SPECIAL, "Unlockdb" );
+               $lc = htmlspecialchars( wfMsg( "unlockconfirm" ) );
+               $lb = htmlspecialchars( wfMsg( "unlockbtn" ) );
+               $titleObj = SpecialPage::getTitleFor( "Unlockdb" );
                $action = $titleObj->escapeLocalURL( "action=submit" );
+               $token = htmlspecialchars( $wgUser->editToken() );
 
                $wgOut->addHTML( <<<END
 
@@ -62,6 +73,7 @@ class DBUnlockForm {
                </td>
        </tr>
 </table>
+<input type="hidden" name="wpEditToken" value="{$token}" />
 </form>
 END
 );
@@ -69,8 +81,7 @@ END
        }
 
        function doSubmit() {
-               global $wgOut, $wgUser, $wgLang;
-               global $wgRequest, $wgReadOnlyFile;
+               global $wgOut, $wgRequest, $wgReadOnlyFile;
 
                $wpLockConfirm = $wgRequest->getCheck( 'wpLockConfirm' );
                if ( ! $wpLockConfirm ) {
@@ -78,22 +89,22 @@ END
                        return;
                }
                if ( @! unlink( $wgReadOnlyFile ) ) {
-                       $wgOut->fileDeleteError( $wgReadOnlyFile );
+                       $wgOut->showFileDeleteError( $wgReadOnlyFile );
                        return;
                }
-               $titleObj = Title::makeTitle( NS_SPECIAL, "Unlockdb" );
+               $titleObj = SpecialPage::getTitleFor( "Unlockdb" );
                $success = $titleObj->getFullURL( "action=success" );
                $wgOut->redirect( $success );
        }
 
        function showSuccess() {
-               global $wgOut, $wgUser;
+               global $wgOut;
                global $ip;
 
                $wgOut->setPagetitle( wfMsg( "unlockdb" ) );
                $wgOut->setSubtitle( wfMsg( "unlockdbsuccesssub" ) );
-               $wgOut->addWikiText( wfMsg( "unlockdbsuccesstext", $ip ) );
+               $wgOut->addWikiMsg( "unlockdbsuccesstext", $ip );
        }
 }
 
-?>
+