Uses properly resized thumbnails for medals in user's profile.
[platal.git] / classes / session.php
index a1e72da..2cb755a 100644 (file)
@@ -28,6 +28,7 @@ class Session
             $_SESSION['challenge'] = sha1(uniqid(rand(), true));
         }
         if (empty($_SESSION['xsrf_token'])) {
+            require_once 'xorg.misc.inc.php';
             $_SESSION['xsrf_token'] = rand_url_id();
         }
         if (!isset($_SESSION['perms']) || !($_SESSION['perms'] instanceof FlagSet)) {
@@ -77,11 +78,6 @@ class Session
         return Session::logged() && Session::v('perms')->hasFlag(PERMS_ADMIN);
     }
 
-    public static function has_xsrf_token()
-    {
-        return Session::has('xsrf_token') && Session::v('xsrf_token') == Env::v('token');
-    }
-
     public static function logged()
     {
         return Session::v('auth', AUTH_PUBLIC) >= AUTH_COOKIE;
@@ -91,6 +87,22 @@ class Session
     {
         return Session::v('auth', AUTH_PUBLIC) >= AUTH_MDP;
     }
+
+    // Anti-XSRF protections.
+    public static function has_xsrf_token()
+    {
+        return Session::has('xsrf_token') && Session::v('xsrf_token') == Env::v('token');
+    }
+
+    public static function assert_xsrf_token()
+    {
+        if (!Session::has_xsrf_token()) {
+            global $page;
+            if ($page instanceof PlatalPage) {
+                $page->kill("L'opĂ©ration n'a pas pu aboutir, merci de rĂ©essayer.");
+            }
+        }
+    }
 }
 
 // {{{ function check_perms()