[opw-web] mod_view_participants: validate program ID



commit fb01c0069aa00164a1e8b4c85bf1518af452431c
Author: Owen W. Taylor <otaylor fishsoup net>
Date:   Sun Sep 21 21:24:29 2014 -0400

    mod_view_participants: validate program ID

 modules/mod_view_participants.php |    5 ++++-
 1 files changed, 4 insertions(+), 1 deletions(-)
---
diff --git a/modules/mod_view_participants.php b/modules/mod_view_participants.php
index 544f7b3..4b4607d 100644
--- a/modules/mod_view_participants.php
+++ b/modules/mod_view_participants.php
@@ -7,9 +7,12 @@
 
 if (!defined('IN_PANDORA')) exit;
 
-$program_id = $core->variable('prg', '');
+$program_id = $core->variable('prg', 0);
 $accepted = $core->variable('accepted', 0) != 0;
 
+$program_data = $cache->get_program_data($program_id);
+$user->restrict($program_data !== null);
+
 // Get the program's participant list
 
 if ($accepted) {


[Date Prev][Date Next]   [Thread Prev][Thread Next]   [Thread Index] [Date Index] [Author Index]