From 4c6a3d7d8ac56b9fea777781b291cfde956a7e9a Mon Sep 17 00:00:00 2001
From: Aleksander Machniak <alec@alec.pl>
Date: Wed, 08 Aug 2012 02:59:53 -0400
Subject: [PATCH] - Check request tokens also in devel_mode

---
 index.php |    2 +-
 1 files changed, 1 insertions(+), 1 deletions(-)

diff --git a/index.php b/index.php
index ab094df..17031f8 100644
--- a/index.php
+++ b/index.php
@@ -225,7 +225,7 @@
 
   // check client X-header to verify request origin
   if ($OUTPUT->ajax_call) {
-    if (rc_request_header('X-Roundcube-Request') != $RCMAIL->get_request_token() && !$RCMAIL->config->get('devel_mode')) {
+    if (rc_request_header('X-Roundcube-Request') != $RCMAIL->get_request_token()) {
       header('HTTP/1.1 403 Forbidden');
       die("Invalid Request");
     }

--
Gitblit v1.9.1