From 037af6890fe6fdb84a08d3c86083e847c90ec0ad Mon Sep 17 00:00:00 2001
From: Aleksander Machniak <alec@alec.pl>
Date: Tue, 22 Oct 2013 08:17:26 -0400
Subject: [PATCH] Fix vulnerability in handling _session argument of utils/save-prefs (#1489382)

---
 skins/larry/templates/identityedit.html |    3 ---
 1 files changed, 0 insertions(+), 3 deletions(-)

diff --git a/skins/larry/templates/identityedit.html b/skins/larry/templates/identityedit.html
index 2657c2d..8d5e622 100644
--- a/skins/larry/templates/identityedit.html
+++ b/skins/larry/templates/identityedit.html
@@ -12,11 +12,8 @@
 <roundcube:object name="identityform" class="propform" size="40" textareacols="40" textarearows="6" />
 </div>
 
-<div id="formfooter">
 <div class="footerleft formbuttons">
 	<roundcube:button command="save" type="input" class="button mainaction" label="save" />
-	<roundcube:button command="delete" type="input" class="button" label="delete" condition="env:action=='edit-identity' && config:identities_level:0<2" />
-</div>
 </div>
 
 <roundcube:include file="/includes/footer.html" />

--
Gitblit v1.9.1