관리자 상태변경 엔드포인트에 요청 출처 검증 추가
- 상품이벤트/개인결제복사/SMS 번호·그룹·폼·업로드/방문로그 삭제 등 POST 기반 상태변경 처리에 check_request_origin() 적용 (스킨 수정 불필요) Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Opus 4.8
parent
82ee3ef438
commit
3d7fa04569
@@ -6,6 +6,8 @@ check_demo();
|
||||
|
||||
auth_check_menu($auth, $sub_menu, "w");
|
||||
|
||||
if (function_exists('check_request_origin')) check_request_origin(G5_ADMIN_URL);
|
||||
|
||||
$post_it_id_count = (isset($_POST['it_id']) && is_array($_POST['it_id'])) ? count($_POST['it_id']) : 0;
|
||||
|
||||
for ($i=0; $i<$post_it_id_count; $i++)
|
||||
|
||||
@@ -8,6 +8,8 @@ ini_set('memory_limit', '50M');
|
||||
|
||||
auth_check_menu($auth, $sub_menu, "w");
|
||||
|
||||
if (function_exists('check_request_origin')) check_request_origin(G5_ADMIN_URL);
|
||||
|
||||
function only_number($n)
|
||||
{
|
||||
return preg_replace('/[^0-9]/', '', (string)$n);
|
||||
|
||||
@@ -4,6 +4,8 @@ include_once('./_common.php');
|
||||
|
||||
auth_check_menu($auth, $sub_menu, 'w');
|
||||
|
||||
if (function_exists('check_request_origin')) check_request_origin(G5_ADMIN_URL);
|
||||
|
||||
$_POST = array_map('trim', $_POST);
|
||||
|
||||
if(!$_POST['pp_name'])
|
||||
|
||||
@@ -4,6 +4,8 @@ include_once('./_common.php');
|
||||
|
||||
auth_check_menu($auth, $sub_menu, "w");
|
||||
|
||||
if (function_exists('check_request_origin')) check_request_origin(G5_ADMIN_URL);
|
||||
|
||||
$post_chk_fg_no = (isset($_POST['chk_fg_no']) && is_array($_POST['chk_fg_no'])) ? $_POST['chk_fg_no'] : array();
|
||||
|
||||
if(!count($post_chk_fg_no))
|
||||
|
||||
@@ -4,6 +4,8 @@ include_once("./_common.php");
|
||||
|
||||
auth_check_menu($auth, $sub_menu, "w");
|
||||
|
||||
if (function_exists('check_request_origin')) check_request_origin(G5_ADMIN_URL);
|
||||
|
||||
$post_cnk = (isset($_POST['chk']) && is_array($_POST['chk'])) ? $_POST['chk'] : array();
|
||||
|
||||
if ($w == 'u') // 업데이트
|
||||
|
||||
@@ -4,6 +4,8 @@ include_once("./_common.php");
|
||||
|
||||
auth_check_menu($auth, $sub_menu, "w");
|
||||
|
||||
if (function_exists('check_request_origin')) check_request_origin(G5_ADMIN_URL);
|
||||
|
||||
$upload_bg_no = isset($_REQUEST['upload_bg_no']) ? (int) $_REQUEST['upload_bg_no'] : 0;
|
||||
$confirm = isset($_REQUEST['confirm']) ? clean_xss_tags($_REQUEST['confirm'], 1, 1) : '';
|
||||
|
||||
|
||||
@@ -4,6 +4,8 @@ include_once("./_common.php");
|
||||
|
||||
auth_check_menu($auth, $sub_menu, "w");
|
||||
|
||||
if (function_exists('check_request_origin')) check_request_origin(G5_ADMIN_URL);
|
||||
|
||||
$g5['title'] = "전화번호부";
|
||||
|
||||
$post_bk_no = (isset($_POST['bk_no']) && is_array($_POST['bk_no'])) ? $_POST['bk_no'] : array();
|
||||
|
||||
@@ -4,6 +4,8 @@ include_once("./_common.php");
|
||||
|
||||
auth_check_menu($auth, $sub_menu, "w");
|
||||
|
||||
if (function_exists('check_request_origin')) check_request_origin(G5_ADMIN_URL);
|
||||
|
||||
$g5['title'] = "휴대폰번호 업데이트";
|
||||
|
||||
$g5['sms5_demo'] = 0;
|
||||
|
||||
@@ -6,6 +6,8 @@ $post_chk = (isset($_POST['chk']) && is_array($_POST['chk'])) ? $_POST['chk'] :
|
||||
|
||||
auth_check_menu($auth, $sub_menu, "w");
|
||||
|
||||
if (function_exists('check_request_origin')) check_request_origin(G5_ADMIN_URL);
|
||||
|
||||
if ($w == 'u') // 업데이트
|
||||
{
|
||||
for ($i=0; $i<count($post_chk); $i++)
|
||||
|
||||
@@ -4,6 +4,8 @@ include_once('./_common.php');
|
||||
|
||||
auth_check_menu($auth, $sub_menu, "w");
|
||||
|
||||
if (function_exists('check_request_origin')) check_request_origin(G5_ADMIN_URL);
|
||||
|
||||
$post_chk_bg_no = isset($_POST['chk_bg_no']) ? $_POST['chk_bg_no'] : array();
|
||||
|
||||
if(!count($post_chk_bg_no))
|
||||
|
||||
@@ -6,6 +6,8 @@ check_demo();
|
||||
|
||||
auth_check_menu($auth, $sub_menu, 'd');
|
||||
|
||||
if (function_exists('check_request_origin')) check_request_origin(G5_ADMIN_URL);
|
||||
|
||||
if ($is_admin != 'super')
|
||||
alert('최고관리자만 접근 가능합니다.');
|
||||
|
||||
|
||||
Reference in New Issue
Block a user