From bd0551b22076b82a6d49e9f7a2b2e0c90a1b2326 Mon Sep 17 00:00:00 2001
From: Aleksander Machniak <alec@alec.pl>
Date: Fri, 05 Feb 2016 07:25:27 -0500
Subject: [PATCH] Secure also downloads of addressbook exports, managesieve script exports and Enigma keys exports

---
 program/steps/utils/error.inc |    9 +++++++++
 1 files changed, 9 insertions(+), 0 deletions(-)

diff --git a/program/steps/utils/error.inc b/program/steps/utils/error.inc
index 3b1d926..7ca933e 100644
--- a/program/steps/utils/error.inc
+++ b/program/steps/utils/error.inc
@@ -72,6 +72,15 @@
     $__error_text .= '<p><i>' . $rcmail->gettext('errfailedrequest') . ":</i><br />\n<tt>//$request_url</tt></p>";
 }
 
+// invalid compose ID
+else if ($ERROR_CODE == 450 && $_SERVER['REQUEST_METHOD'] == 'GET' && $rcmail->action == 'compose') {
+    $url = $rcmail->url('compose');
+
+    $__error_title = strtoupper($rcmail->gettext('errcomposesession'));
+    $__error_text  = nl2br($rcmail->gettext('errcomposesessionexplain'))
+        . '<p>' . html::a($url, $rcmail->gettext('clicktocompose')) . '</p>';
+}
+
 // database connection error
 else if ($ERROR_CODE == 601) {
     $__error_title = "CONFIGURATION ERROR";

--
Gitblit v1.9.1