diff --git a/contrib/admin/main.php b/contrib/admin/main.php index 87d7461b..5a34a376 100644 --- a/contrib/admin/main.php +++ b/contrib/admin/main.php @@ -52,7 +52,7 @@ class AdminPage implements Extension { } if(($event instanceof PageRequestEvent) && $event->page_matches("admin_utils")) { - if($user->is_admin()) { + if($user->is_admin() && $user->check_auth_token()) { log_info("admin", "Util: {$_POST['action']}"); set_time_limit(0); $redirect = false; diff --git a/contrib/admin/theme.php b/contrib/admin/theme.php index f732c45b..dce3b26d 100644 --- a/contrib/admin/theme.php +++ b/contrib/admin/theme.php @@ -17,8 +17,11 @@ class AdminPageTheme extends Themelet { * 'purge unused tags' */ public function display_form(Page $page) { + global $user; + $html = "