From 037af6890fe6fdb84a08d3c86083e847c90ec0ad Mon Sep 17 00:00:00 2001
From: Aleksander Machniak <alec@alec.pl>
Date: Tue, 22 Oct 2013 08:17:26 -0400
Subject: [PATCH] Fix vulnerability in handling _session argument of utils/save-prefs (#1489382)

---
 skins/larry/includes/header.html |   15 +++++++++++++--
 1 files changed, 13 insertions(+), 2 deletions(-)

diff --git a/skins/larry/includes/header.html b/skins/larry/includes/header.html
index 9187c6f..f2efb8e 100644
--- a/skins/larry/includes/header.html
+++ b/skins/larry/includes/header.html
@@ -1,26 +1,37 @@
 <div id="header">
 <div id="topline">
 	<div class="topleft">
+		<roundcube:container name="topline-left" id="topline-left" />
 		<roundcube:button name="about" type="link" label="about" class="about-link" onclick="UI.show_about(this);return false" />
 		<roundcube:if condition="config:support_url" />
 		<a href="<roundcube:var name='config:support_url' />" target="_blank" class="support-link" id="supportlink"><roundcube:label name="support" /></a>
 		<roundcube:endif />
 	</div>
+	<roundcube:container name="topline-center" id="topline-center" />
 	<div class="topright">
-	<span class="username"><roundcube:object name="username" /></span>
-	<roundcube:button command="logout" label="logout" class="button-logout" />
+	<roundcube:container name="topline-right" id="topline-right" />
+	<roundcube:if condition="!env:extwin &amp;&amp; !env:framed" />
+		<span class="username"><roundcube:object name="username" /></span>
+		<roundcube:button command="logout" label="logout" class="button-logout" />
+	<roundcube:elseif condition="env:extwin" />
+		<roundcube:button command="close" label="close" class="closelink" />
+	<roundcube:endif />
 	</div>
 </div>
 
+<roundcube:if condition="!env:extwin &amp;&amp; !env:framed" />
 <div id="topnav">
 	<div id="taskbar" class="topright">
 	<roundcube:button command="mail" label="mail" class="button-mail" classSel="button-mail button-selected" innerClass="button-inner" />
 	<roundcube:button command="addressbook" label="addressbook" class="button-addressbook" classSel="button-addressbook button-selected" innerClass="button-inner" />
 	<roundcube:container name="taskbar" id="taskbar" />
 	<roundcube:button command="settings" label="settings" class="button-settings" classSel="button-settings button-selected" innerClass="button-inner" />
+	<roundcube:button command="logout" label="logout" class="button-logout" classSel="button-logout" innerClass="button-inner" />
+	<span class="minmodetoggle"></span>
 	</div>
 	<roundcube:object name="logo" src="/images/roundcube_logo.png" id="toplogo" border="0" alt="Logo" onclick="rcmail.command('switch-task','mail');return false;" />
 </div>
+<roundcube:endif />
 
 <br style="clear:both" />
 </div>

--
Gitblit v1.9.1