diff options
Diffstat (limited to 'mod/notifications/actions/save.php')
| -rw-r--r-- | mod/notifications/actions/save.php | 13 |
1 files changed, 11 insertions, 2 deletions
diff --git a/mod/notifications/actions/save.php b/mod/notifications/actions/save.php index 18f243254..3fe0001a3 100644 --- a/mod/notifications/actions/save.php +++ b/mod/notifications/actions/save.php @@ -6,9 +6,18 @@ * @package ElggNotifications */ -$user = get_loggedin_user(); +$current_user = elgg_get_logged_in_user_entity(); + +$guid = (int) get_input('guid', 0); +if (!$guid || !($user = get_entity($guid))) { + forward(); +} +if (($user->guid != $current_user->guid) && !$current_user->isAdmin()) { + forward(); +} global $NOTIFICATION_HANDLERS; +$subscriptions = array(); foreach($NOTIFICATION_HANDLERS as $method => $foo) { $subscriptions[$method] = get_input($method.'subscriptions'); $personal[$method] = get_input($method.'personal'); @@ -31,4 +40,4 @@ foreach($subscriptions as $key => $subscription) { system_message(elgg_echo('notifications:subscriptions:success')); -forward($_SERVER['HTTP_REFERER']); +forward(REFERER); |
