Exemple #1
0
    // don't check for valid request tokens in these actions
    $request_check_whitelist = array('login' => 1, 'spell' => 1);
    // check client X-header to verify request origin
    if ($OUTPUT->ajax_call) {
        if (rc_request_header('X-Roundcube-Request') != $RCMAIL->get_request_token() && !$RCMAIL->config->get('devel_mode')) {
            header('HTTP/1.1 403 Forbidden');
            die("Invalid Request");
        }
    } else {
        if (!empty($_POST) && !$request_check_whitelist[$RCMAIL->action] && !$RCMAIL->check_request()) {
            $OUTPUT->show_message('invalidrequest', 'error');
            $OUTPUT->send($RCMAIL->task);
        }
    }
    // check referer if configured
    if (!$request_check_whitelist[$RCMAIL->action] && $RCMAIL->config->get('referer_check') && !rcube_check_referer()) {
        raise_error(array('code' => 403, 'type' => 'php', 'message' => "Referer check failed"), true, true);
    }
}
// we're ready, user is authenticated and the request is safe
$plugin = $RCMAIL->plugins->exec_hook('ready', array('task' => $RCMAIL->task, 'action' => $RCMAIL->action));
$RCMAIL->set_task($plugin['task']);
$RCMAIL->action = $plugin['action'];
// handle special actions
if ($RCMAIL->action == 'keep-alive') {
    $OUTPUT->reset();
    $RCMAIL->plugins->exec_hook('keep_alive', array());
    $OUTPUT->send();
} else {
    if ($RCMAIL->action == 'save-pref') {
        include INSTALL_PATH . 'program/steps/utils/save_pref.inc';
Exemple #2
0
    $request_check_whitelist = array('login' => 1, 'spell' => 1, 'spell_html' => 1);
    if (!$request_check_whitelist[$RCMAIL->action]) {
        // check client X-header to verify request origin
        if ($OUTPUT->ajax_call) {
            if (rc_request_header('X-Roundcube-Request') != $RCMAIL->get_request_token()) {
                header('HTTP/1.1 403 Forbidden');
                die("Invalid Request");
            }
        } else {
            if (!empty($_POST) && !$RCMAIL->check_request()) {
                $OUTPUT->show_message('invalidrequest', 'error');
                $OUTPUT->send($RCMAIL->task);
            }
        }
        // check referer if configured
        if ($RCMAIL->config->get('referer_check') && !rcube_check_referer()) {
            raise_error(array('code' => 403, 'type' => 'php', 'message' => "Referer check failed"), true, true);
        }
    }
}
// we're ready, user is authenticated and the request is safe
$plugin = $RCMAIL->plugins->exec_hook('ready', array('task' => $RCMAIL->task, 'action' => $RCMAIL->action));
$RCMAIL->set_task($plugin['task']);
$RCMAIL->action = $plugin['action'];
// handle special actions
if ($RCMAIL->action == 'keep-alive') {
    $OUTPUT->reset();
    $RCMAIL->plugins->exec_hook('keep_alive', array());
    $OUTPUT->send();
} else {
    if ($RCMAIL->action == 'save-pref') {