security precausion, dont allow to ignore the acl via xmlrpc

This commit is contained in:
Ralf Becker 2005-11-23 14:15:11 +00:00
parent 365c891649
commit 199278aef0

View File

@ -229,6 +229,8 @@ class bocalendar
// some defaults for xmlrpc // some defaults for xmlrpc
if (!isset($params['date_format'])) $params['date_format'] = $this->xmlrpc_date_format; if (!isset($params['date_format'])) $params['date_format'] = $this->xmlrpc_date_format;
if (!isset($params['enum_recuring'])) $params['enum_recuring'] = false; if (!isset($params['enum_recuring'])) $params['enum_recuring'] = false;
// security precausion
unset($params['ignore_acl']);
$events =& $this->cal->search($params); $events =& $this->cal->search($params);