From 97acdb6f44223220fa33b0d62a3e6ff07804315b Mon Sep 17 00:00:00 2001 From: ryan Date: Sun, 28 May 2006 23:33:05 +0000 Subject: [PATCH] nonce and comment fixes from Juergen. fixes #2748 git-svn-id: http://svn.automattic.com/wordpress/branches/2.0@3808 1a063a9b-81f0-0310-95a4-ce76da25c4cd --- wp-admin/edit-comments.php | 8 ++++---- wp-admin/list-manipulation.php | 1 + wp-admin/moderation.php | 2 +- wp-admin/post.php | 1 + 4 files changed, 7 insertions(+), 5 deletions(-) diff --git a/wp-admin/edit-comments.php b/wp-admin/edit-comments.php index 7e88d2e7a7..5bb4c6e4d5 100644 --- a/wp-admin/edit-comments.php +++ b/wp-admin/edit-comments.php @@ -98,13 +98,13 @@ if ('view' == $mode) {

comment_post_ID) ) { echo " | comment_ID."\">" . __('Edit Comment') . ""; - echo ' | " . __('Delete Comment') . ' '; + echo ' | " . __('Delete Comment') . ' '; } // end if any comments to show // Get post title if ( current_user_can('edit_post', $comment->comment_post_ID) ) { $post_title = $wpdb->get_var("SELECT post_title FROM $wpdb->posts WHERE ID = $comment->comment_post_ID"); $post_title = ('' == $post_title) ? "# $comment->comment_post_ID" : $post_title; - ?> + ?> | |

@@ -151,13 +151,13 @@ if ('view' == $mode) { comment_post_ID) ) { echo "" . __('Edit') . ""; } ?> comment_post_ID) ) { - echo "comment_post_ID."&comment=".$comment->comment_ID."\" onclick=\"return confirm('" . __("You are about to delete this comment\\n \'Cancel\' to stop, \'OK\' to delete.") . "')\" class='delete'>" . __('Delete') . ""; } ?> + echo "comment_post_ID."&comment=".$comment->comment_ID, 'delete-comment_' . $comment->comment_ID) . "\" onclick=\"return confirm('" . __("You are about to delete this comment.\\n \'Cancel\' to stop, \'OK\' to delete.") . "')\" class='delete'>" . __('Delete') . ""; } ?>

-

')" />

+

')" />

comment_ID.'">' . __('Edit') . ' | ';?> | comment_post_ID."&comment=".$comment->comment_ID."\" onclick=\"return deleteSomething( 'comment', $comment->comment_ID, '" . __("You are about to delete this comment.\\n"Cancel" to stop, "OK" to delete.") . "' );\">" . __('Delete just this comment') . " | "; ?> +echo " comment_post_ID."&comment=".$comment->comment_ID, 'delete-comment_' . $comment->comment_ID) . "\" onclick=\"return deleteSomething( 'comment', $comment->comment_ID, '" . __("You are about to delete this comment.\\n"Cancel" to stop, "OK" to delete.") . "' );\">" . __('Delete just this comment') . " | "; ?> diff --git a/wp-admin/post.php b/wp-admin/post.php index f639a5fd2e..d608b3cd3d 100644 --- a/wp-admin/post.php +++ b/wp-admin/post.php @@ -203,6 +203,7 @@ case 'confirmdeletecomment': echo "\n"; echo "\n"; echo "\n"; + wp_nonce_field('delete-comment_' . $comment->comment_ID); echo ""; echo "  "; echo "\n";