mirror of
https://github.com/prasathmani/tinyfilemanager
synced 2026-03-14 12:45:51 +01:00
Advanced Search not working for read-only users #1325
This commit is contained in:
parent
dd2e22781b
commit
dd79258999
1 changed files with 5 additions and 1 deletions
|
|
@ -459,7 +459,7 @@ unset($p, $use_auth, $iconv_input_encoding, $use_highlightjs, $highlightjs_style
|
|||
/*************************** ACTIONS ***************************/
|
||||
|
||||
// Handle all AJAX Request
|
||||
if ((isset($_SESSION[FM_SESSION_ID]['logged'], $auth_users[$_SESSION[FM_SESSION_ID]['logged']]) || !FM_USE_AUTH) && isset($_POST['ajax'], $_POST['token']) && !FM_READONLY) {
|
||||
if ((isset($_SESSION[FM_SESSION_ID]['logged'], $auth_users[$_SESSION[FM_SESSION_ID]['logged']]) || !FM_USE_AUTH) && isset($_POST['ajax'], $_POST['token'])) {
|
||||
if (!verifyToken($_POST['token'])) {
|
||||
header('HTTP/1.0 401 Unauthorized');
|
||||
die("Invalid Token.");
|
||||
|
|
@ -473,6 +473,10 @@ if ((isset($_SESSION[FM_SESSION_ID]['logged'], $auth_users[$_SESSION[FM_SESSION_
|
|||
exit();
|
||||
}
|
||||
|
||||
if(FM_READONLY){
|
||||
exit();
|
||||
}
|
||||
|
||||
// save editor file
|
||||
if (isset($_POST['type']) && $_POST['type'] == "save") {
|
||||
// get current path
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue