- Check request tokens also in devel_mode

Conflicts:

	index.php
pull/20/head
Aleksander Machniak 12 years ago
parent 358957e73e
commit 4c6a3d7d8a

@ -225,7 +225,7 @@ else {
// check client X-header to verify request origin
if ($OUTPUT->ajax_call) {
if (rc_request_header('X-Roundcube-Request') != $RCMAIL->get_request_token() && !$RCMAIL->config->get('devel_mode')) {
if (rc_request_header('X-Roundcube-Request') != $RCMAIL->get_request_token()) {
header('HTTP/1.1 403 Forbidden');
die("Invalid Request");
}

Loading…
Cancel
Save