@@ -45,7 +45,7 @@ public function __construct(string $id, string $headline = '')
4545 */
4646 public function createContentAssignUser (User $ user , bool $ assignRegistration = false )
4747 {
48- global $ gL10n , $ gSettingsManager , $ gCurrentUser , $ gDb , $ gProfileFields , $ gCurrentOrganization ;
48+ global $ gL10n , $ gSettingsManager , $ gCurrentUser , $ gDb , $ gProfileFields , $ gCurrentOrganization, $ gCurrentSession ;
4949
5050 $ templateData = array ();
5151 $ userUuid = $ user ->getValue ('usr_uuid ' );
@@ -127,11 +127,13 @@ public function createContentAssignUser(User $user, bool $assignRegistration = f
127127 $ button ['icon ' ] = 'bi-person-check-fill ' ;
128128 $ button ['url ' ] = SecurityUtils::encodeUrl (ADMIDIO_URL . FOLDER_MODULES . '/registration.php ' , array ('user_uuid ' => $ userUuid , 'user_uuid_assigned ' => $ similarUser ->getValue ('usr_uuid ' ), 'mode ' => 'assign_member ' ));
129129 }
130+ $ button ['csrfToken ' ] = $ gCurrentSession ->getCsrfToken ();
130131 }
131132 } else {
132133 // found user is NOT a member of this organization yet
133134 $ button ['label ' ] = $ gL10n ->get ('SYS_ASSIGN_MEMBERSHIP ' );
134135 $ button ['icon ' ] = 'bi-person-check-fill ' ;
136+ $ button ['csrfToken ' ] = $ gCurrentSession ->getCsrfToken ();
135137
136138 if ($ assignRegistration ) {
137139 $ button ['url ' ] = SecurityUtils::encodeUrl (ADMIDIO_URL . FOLDER_MODULES . '/registration.php ' , array ('user_uuid ' => $ userUuid , 'user_uuid_assigned ' => $ similarUser ->getValue ('usr_uuid ' ), 'mode ' => 'assign_user ' ));
@@ -156,6 +158,7 @@ public function createContentAssignUser(User $user, bool $assignRegistration = f
156158 $ templateData [] = $ templateRow ;
157159 }
158160
161+ $ this ->smarty ->assign ('csrfToken ' , $ gCurrentSession ->getCsrfToken ());
159162 $ this ->smarty ->assign ('similarUsers ' , $ templateData );
160163 $ this ->smarty ->assign ('l10n ' , $ gL10n );
161164 $ this ->pageContent .= $ this ->smarty ->fetch ('modules/contacts.assign.tpl ' );
0 commit comments