관리자 상태변경 엔드포인트에 요청 출처 검증 추가

- 상품이벤트/개인결제복사/SMS 번호·그룹·폼·업로드/방문로그 삭제 등
  POST 기반 상태변경 처리에 check_request_origin() 적용 (스킨 수정 불필요)

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
thisgun
2026-07-13 07:20:32 +00:00
co-authored by Claude Opus 4.8
parent 82ee3ef438
commit 3d7fa04569
11 changed files with 22 additions and 0 deletions
+2
View File
@@ -6,6 +6,8 @@ check_demo();
auth_check_menu($auth, $sub_menu, "w");
if (function_exists('check_request_origin')) check_request_origin(G5_ADMIN_URL);
$post_it_id_count = (isset($_POST['it_id']) && is_array($_POST['it_id'])) ? count($_POST['it_id']) : 0;
for ($i=0; $i<$post_it_id_count; $i++)
+2
View File
@@ -8,6 +8,8 @@ ini_set('memory_limit', '50M');
auth_check_menu($auth, $sub_menu, "w");
if (function_exists('check_request_origin')) check_request_origin(G5_ADMIN_URL);
function only_number($n)
{
return preg_replace('/[^0-9]/', '', (string)$n);
+2
View File
@@ -4,6 +4,8 @@ include_once('./_common.php');
auth_check_menu($auth, $sub_menu, 'w');
if (function_exists('check_request_origin')) check_request_origin(G5_ADMIN_URL);
$_POST = array_map('trim', $_POST);
if(!$_POST['pp_name'])
+2
View File
@@ -4,6 +4,8 @@ include_once('./_common.php');
auth_check_menu($auth, $sub_menu, "w");
if (function_exists('check_request_origin')) check_request_origin(G5_ADMIN_URL);
$post_chk_fg_no = (isset($_POST['chk_fg_no']) && is_array($_POST['chk_fg_no'])) ? $_POST['chk_fg_no'] : array();
if(!count($post_chk_fg_no))
+2
View File
@@ -4,6 +4,8 @@ include_once("./_common.php");
auth_check_menu($auth, $sub_menu, "w");
if (function_exists('check_request_origin')) check_request_origin(G5_ADMIN_URL);
$post_cnk = (isset($_POST['chk']) && is_array($_POST['chk'])) ? $_POST['chk'] : array();
if ($w == 'u') // 업데이트
+2
View File
@@ -4,6 +4,8 @@ include_once("./_common.php");
auth_check_menu($auth, $sub_menu, "w");
if (function_exists('check_request_origin')) check_request_origin(G5_ADMIN_URL);
$upload_bg_no = isset($_REQUEST['upload_bg_no']) ? (int) $_REQUEST['upload_bg_no'] : 0;
$confirm = isset($_REQUEST['confirm']) ? clean_xss_tags($_REQUEST['confirm'], 1, 1) : '';
+2
View File
@@ -4,6 +4,8 @@ include_once("./_common.php");
auth_check_menu($auth, $sub_menu, "w");
if (function_exists('check_request_origin')) check_request_origin(G5_ADMIN_URL);
$g5['title'] = "전화번호부";
$post_bk_no = (isset($_POST['bk_no']) && is_array($_POST['bk_no'])) ? $_POST['bk_no'] : array();
+2
View File
@@ -4,6 +4,8 @@ include_once("./_common.php");
auth_check_menu($auth, $sub_menu, "w");
if (function_exists('check_request_origin')) check_request_origin(G5_ADMIN_URL);
$g5['title'] = "휴대폰번호 업데이트";
$g5['sms5_demo'] = 0;
+2
View File
@@ -6,6 +6,8 @@ $post_chk = (isset($_POST['chk']) && is_array($_POST['chk'])) ? $_POST['chk'] :
auth_check_menu($auth, $sub_menu, "w");
if (function_exists('check_request_origin')) check_request_origin(G5_ADMIN_URL);
if ($w == 'u') // 업데이트
{
for ($i=0; $i<count($post_chk); $i++)
+2
View File
@@ -4,6 +4,8 @@ include_once('./_common.php');
auth_check_menu($auth, $sub_menu, "w");
if (function_exists('check_request_origin')) check_request_origin(G5_ADMIN_URL);
$post_chk_bg_no = isset($_POST['chk_bg_no']) ? $_POST['chk_bg_no'] : array();
if(!count($post_chk_bg_no))
+2
View File
@@ -6,6 +6,8 @@ check_demo();
auth_check_menu($auth, $sub_menu, 'd');
if (function_exists('check_request_origin')) check_request_origin(G5_ADMIN_URL);
if ($is_admin != 'super')
alert('최고관리자만 접근 가능합니다.');