fix(admin): verify CSRF token in message admin Mods [#139] (#264)

sendMessage, massmessage and sysmessage are POSTed to directly, bypassing
admin.php's central csrf_verify(). Add csrf_verify() (after the admin access
check, via the shared GameEngine/Admin/csrf.php) and csrf_field() in their
forms (Newmessage.tpl, massmessage.tpl, sysmessage.tpl; the mass/sys templates
have both a prepare and an execute form).

Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
Ferywir
2026-06-23 10:49:32 +02:00
committed by GitHub
parent 5f86fdcbf6
commit 6472b30bd2
6 changed files with 20 additions and 1 deletions
+1
View File
@@ -54,6 +54,7 @@ $user = $database->getUserArray($id,1);
</div>
<form method="post" action="../GameEngine/Admin/Mods/sendMessage.php" name="msg">
<?php echo csrf_field(); ?>
<div class="msg-body">
<input type="hidden" name="uid" value="<?php echo $id; ?>">
+2
View File
@@ -66,6 +66,7 @@ $_SESSION['mass_color'] = $_SESSION['mass_color'] ?? 'black';
<b>Subject:</b> <span style="color:<?=$_SESSION['mass_color']?>"><?=htmlspecialchars($_SESSION['mass_subject'])?></span>
</div>
<form action="../GameEngine/Admin/Mods/massmessage.php" method="POST" class="massmsg-form">
<?php echo csrf_field(); ?>
<input type="hidden" name="admid" value="<?=$id?>">
<input type="hidden" name="action" value="execute">
<button type="submit" name="confirm" value="Yes" style="background:#27ae60">✓ Yes, Send</button>
@@ -80,6 +81,7 @@ $_SESSION['mass_color'] = $_SESSION['mass_color'] ?? 'black';
<?php else:?>
<form action="../GameEngine/Admin/Mods/massmessage.php" method="POST" class="massmsg-form">
<?php echo csrf_field(); ?>
<input type="hidden" name="admid" value="<?=$id?>">
<input type="hidden" name="action" value="prepare">
+2 -1
View File
@@ -68,6 +68,7 @@ $_SESSION['sys_color'] = $_SESSION['sys_color'] ?? 'black';
</div>
<form action="../GameEngine/Admin/Mods/sysmessage.php" method="POST" class="sysmsg-form">
<?php echo csrf_field(); ?>
<input type="hidden" name="admid" value="<?=$id?>">
<input type="hidden" name="action" value="execute">
@@ -84,7 +85,7 @@ $_SESSION['sys_color'] = $_SESSION['sys_color'] ?? 'black';
<?php else: ?>
<form action="../GameEngine/Admin/Mods/sysmessage.php" method="POST" class="sysmsg-form">
<?php echo csrf_field(); ?>
<input type="hidden" name="admid" value="<?=$id?>">
<input type="hidden" name="action" value="prepare">